In ConnectWise PSA versions older than 2026.1, Time Entry notes stored in the Time Entry Audit Trail may be rendered without applying output encoding to certain content. Under specific conditions, this may allow stored script code to execute in the context of a user’s browser when the affected content is displayed.
History

Fri, 16 Jan 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 16 Jan 2026 14:00:00 +0000

Type Values Removed Values Added
Description In ConnectWise PSA versions older than 2026.1, Time Entry notes stored in the Time Entry Audit Trail may be rendered without applying output encoding to certain content. Under specific conditions, this may allow stored script code to execute in the context of a user’s browser when the affected content is displayed.
Title Stored XSS in Time Entry Audit Trail
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ConnectWise

Published:

Updated: 2026-01-16T14:07:48.888Z

Reserved: 2026-01-07T21:31:57.230Z

Link: CVE-2026-0695

cve-icon Vulnrichment

Updated: 2026-01-16T14:07:43.518Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-01-16T14:15:54.793

Modified: 2026-01-16T15:55:12.257

Link: CVE-2026-0695

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.