VYPR
Unrated severityNVD Advisory· Published Jan 16, 2026· Updated Jan 27, 2026

Stored XSS in Time Entry Audit Trail

CVE-2026-0695

Description

In ConnectWise PSA versions older than 2026.1, Time Entry notes stored in the Time Entry Audit Trail may be rendered without applying output encoding to certain content. Under specific conditions, this may allow stored script code to execute in the context of a user’s browser when the affected content is displayed.

Affected products

2
  • Connectwise/PSAllm-fuzzy
    Range: <2026.1
  • ConnectWise/PSAv5
    Range: All versions prior to 2026.1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.