CVE-2026-0696

Session Cookies Missing HttpOnly Attribute In ConnectWise PSA

Discovered by Petar Sever on behalf of The Missing Link Security

Vulnerability Details

In ConnectWise PSA prior to 2026.1 certain session cookies do not set the HttpOnly attribute, potentially allowing client-side scripts to access them.

Affected Versions

Before 2026.1

Fixed Versions

Fixed in: 2026.1

Latest News