HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2026-0695

CVSS 8.7v3.1pub. 2026-01-16upd. 2026-01-27

In ConnectWise PSA versions older than 2026.1, Time Entry notes stored in the Time Entry Audit Trail may be rendered without applying output encoding to certain content. Under specific conditions, this may allow stored script code to execute in the context of a user’s browser when the affected content is displayed.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
  • Connectwise Professional Service Automation

    APP
    Connectwise
    < 2026.1
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
XSS
CWE
References

Related vulnerabilities

CVE-2026-0696MEDIUM6.5same product

W wersjach ConnectWise PSA starszych niż 2026.1 niektóre ciasteczka sesji nie miały ustawionego atrybutu HttpO...

CVE-2025-7204MEDIUM6.5same product

In ConnectWise PSA versions older than 2025.9, a vulnerability exists where authenticated users could gain acc...

CVE-2024-1709CRITICAL10.0⚠ KEVPL ✓same vendor

Authentication Bypass w ConnectWise ScreenConnect — bezpośredni dostęp do systemów

CVE-2017-18362CRITICAL9.8⚠ KEVPL ✓same vendor

SQL Injection w ConnectWise ManagedITSync dla Kaseya VSA — nieuwierzytelniony dostęp do bazy

CVE-2025-14265CRITICAL9.1PL ✓same vendor

ConnectWise ScreenConnect — instalacja niezaufanych rozszerzeń z RCE