In ConnectWise PSA versions older than 2026.1, Time Entry notes stored in the Time Entry Audit Trail may be rendered without applying output encoding to certain content. Under specific conditions, this may allow stored script code to execute in the context of a user’s browser when the affected content is displayed.
Advisories

No advisories yet.

Fixes

Solution

Cloud Cloud instances are automatically being updated to the latest ConnectWise PSA release. On-premise Apply the 2026.1 release patches and ensure all desktop clients are up to date.


Workaround

No workaround given by the vendor.

History

Tue, 27 Jan 2026 12:30:00 +0000

Type Values Removed Values Added
References

Fri, 23 Jan 2026 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Connectwise professional Service Automation
CPEs cpe:2.3:a:connectwise:professional_service_automation:*:*:*:*:*:*:*:*
Vendors & Products Connectwise professional Service Automation

Mon, 19 Jan 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Connectwise
Connectwise psa
Vendors & Products Connectwise
Connectwise psa

Fri, 16 Jan 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 16 Jan 2026 14:00:00 +0000

Type Values Removed Values Added
Description In ConnectWise PSA versions older than 2026.1, Time Entry notes stored in the Time Entry Audit Trail may be rendered without applying output encoding to certain content. Under specific conditions, this may allow stored script code to execute in the context of a user’s browser when the affected content is displayed.
Title Stored XSS in Time Entry Audit Trail
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: ConnectWise

Published:

Updated: 2026-01-27T12:14:38.371Z

Reserved: 2026-01-07T21:31:57.230Z

Link: CVE-2026-0695

cve-icon Vulnrichment

Updated: 2026-01-16T14:07:43.518Z

cve-icon NVD

Status : Modified

Published: 2026-01-16T14:15:54.793

Modified: 2026-01-27T13:15:54.260

Link: CVE-2026-0695

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-01-19T09:20:55Z

Weaknesses