Feed/CVE-2026-0696
CVE-2026-0696MEDIUMCVSS 6.5

CVE-2026-0696

Published Jan 16, 2026·Updated Jun 17, 2026

NVD Description

In ConnectWise PSA versions older than 2026.1, certain session cookies were not set with the HttpOnly attribute. In some scenarios, this could allow client-side scripts access to session cookie values.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free