216.73.216.6

CVE-2026-0695

· Published 16/01/2026 14:15 · Modified 16/01/2026 15:55

Labels: CVE-2026-0695 2026-01-167d616e1a-3288-43b1-a0dd-0a65d3e70a49CVE-2026-0695CWE-79

Essential information

Published
16/01/2026 14:15
Modified
16/01/2026 15:55
Author
Creator
CVSS
8.7 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

CVSS metrics

Description

In ConnectWise PSA versions older than 2026.1, Time Entry notes stored in the Time Entry Audit Trail may be rendered without applying output encoding to certain content. Under specific conditions, this may allow stored script code to execute in the context of a user’s browser when the affected content is displayed.

NVD status

Status
Undergoing Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
7d616e1a-3288-43b1-a0dd-0a65d3e70a49
NVD
View on NVD

Affected products (CPE)

ProductCPE
connectwise / connectwise psa cpe:2.3:a:connectwise:connectwise_psa:<2026.1:*:*:*:*:*:*:*

References