CVE-2026-0696: Session Cookies Missing HttpOnly Attribute
In ConnectWise PSA versions older than 2026.1, certain session cookies were not set with the HttpOnly attribute. In some scenarios, this could allow client-side scripts access to session cookie values.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0696?
CVE-2026-0696 has a medium severity rating due to the potential exposure of session cookies to client-side scripts.
How do I fix CVE-2026-0696?
To fix CVE-2026-0696, upgrade ConnectWise PSA to version 2026.1 or later where the HttpOnly attribute is properly configured on session cookies.
What are the consequences of CVE-2026-0696?
The consequences of CVE-2026-0696 include the risk of session hijacking if an attacker can access session cookie values via client-side scripts.
Which versions of ConnectWise PSA are affected by CVE-2026-0696?
Versions of ConnectWise PSA prior to 2026.1 are affected by CVE-2026-0696.
Where can I find more information about CVE-2026-0696?
More information about CVE-2026-0696 can typically be found in the release notes and security bulletins provided by ConnectWise.