Unrated severityNVD Advisory· Published Jan 16, 2026· Updated Jan 27, 2026
Session Cookies Missing HttpOnly Attribute
CVE-2026-0696
Description
In ConnectWise PSA versions older than 2026.1, certain session cookies were not set with the HttpOnly attribute. In some scenarios, this could allow client-side scripts access to session cookie values.
Affected products
2- Range: < 2026.1
- ConnectWise/PSAv5Range: All versions prior to 2026.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.