CVE-2026-0695

Stored XSS In Time Entry Audit Trail In ConnectWise PSA

Discovered by Petar Sever on behalf of The Missing Link Security

Vulnerability Details

ConnectWise PSA prior to 2026.1 is vulnerable to a stored cross-site scripting attack via the Time Entry Audit Trail component. Under specific conditions, this may allow an attacker to hijack a victim user’s session and perform actions in their security context.

Affected Versions

Before 2026.1

Fixed Versions

Fixed in: 2026.1

Latest News