In ConnectWise PSA versions older than 2026.1, certain session cookies were not set with the HttpOnly attribute. In some scenarios, this could allow client-side scripts access to session cookie values.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-0696.json"
[ { "events": [ { "introduced": "0" }, { "fixed": "2026.1" } ] } ]