CVE-2026-0695: Stored XSS in Time Entry Audit Trail
In ConnectWise PSA versions older than 2026.1, Time Entry notes stored in the Time Entry Audit Trail may be rendered without applying output encoding to certain content. Under specific conditions, this may allow stored script code to execute in the context of a user’s browser when the affected content is displayed.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0695?
CVE-2026-0695 is classified as a high severity vulnerability due to the potential for stored XSS attacks.
How do I fix CVE-2026-0695?
To mitigate CVE-2026-0695, upgrade ConnectWise PSA to version 2026.1 or later.
What is the impact of CVE-2026-0695 on ConnectWise PSA?
CVE-2026-0695 allows for the execution of malicious scripts, potentially compromising user sessions and data.
Which versions of ConnectWise PSA are affected by CVE-2026-0695?
CVE-2026-0695 affects all versions of ConnectWise PSA prior to 2026.1.
What type of vulnerability is CVE-2026-0695?
CVE-2026-0695 is a stored cross-site scripting (XSS) vulnerability found in the Time Entry Audit Trail.