MEDIUM✓ PATCH🇬🇧 English

CVE-2026-0696

CVSS 6.5v3.1pub. 2026-01-16upd. 2026-01-27

W wersjach ConnectWise PSA starszych niż 2026.1 niektóre ciasteczka sesji nie miały ustawionego atrybutu HttpOnly. W niektórych scenariuszach mogło to umożliwić skryptom po stronie klienta dostęp do wartości ciasteczek sesji.

Pokaż oryginał (EN)

In ConnectWise PSA versions older than 2026.1, certain session cookies were not set with the HttpOnly attribute. In some scenarios, this could allow client-side scripts access to session cookie values.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
  • Connectwise Professional Service Automation

    APP
    Connectwise
    < 2026.1
🟢
PATCH DOSTĘPNY
Aktualizacja od producenta gotowa. Wdrożenie w ramach standardowego cyklu.
CWE
Referencje

Powiązane podatności

CVE-2026-0695HIGH8.7ten sam produkt

In ConnectWise PSA versions older than 2026.1, Time Entry notes stored in the Time Entry Audit Trail may be re...

CVE-2025-7204MEDIUM6.5ten sam produkt

In ConnectWise PSA versions older than 2025.9, a vulnerability exists where authenticated users could gain acc...

CVE-2024-1709CRITICAL10.0⚠ KEVPL ✓ten sam vendor

Authentication Bypass w ConnectWise ScreenConnect — bezpośredni dostęp do systemów

CVE-2017-18362CRITICAL9.8⚠ KEVPL ✓ten sam vendor

SQL Injection w ConnectWise ManagedITSync dla Kaseya VSA — nieuwierzytelniony dostęp do bazy

CVE-2025-14265CRITICAL9.1PL ✓ten sam vendor

ConnectWise ScreenConnect — instalacja niezaufanych rozszerzeń z RCE