ConnectWise PSA Sensitive Cookie Without 'HttpOnly' Flag Vulnerability

Vulnerability

A vulnerability exists in ConnectWise PSA versions prior to 2026.1, where certain session cookies were not configured with the 'HttpOnly' attribute. This oversight could potentially allow client-side scripts to access session cookie values, posing a risk of cookie theft or session hijacking.

Impact

Exploitation of this vulnerability could lead to unauthorized access to session cookies, allowing for potential session hijacking.

Remediation

Users can upgrade to the ConnectWise PSA 2026.1 release. For on-premise installations, apply the 2026.1 release patches and ensure all desktop clients are up to date.

Added: Jan 16, 2026, 2:20 PM
Updated: Jan 16, 2026, 4:00 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
5.8
remediation
0.0
relevance
2.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.