Back

HIGH

Stored XSS in Time Entry Audit Trail

Published Jan 16, 2026

Description

In ConnectWise PSA versions older than 2026.1, Time Entry notes stored in the Time Entry Audit Trail may be rendered without applying output encoding to certain content. Under specific conditions, this may allow stored script code to execute in the context of a user’s browser when the affected content is displayed.

Affected products

Remediation

Vendor solution

Cloud Cloud instances are automatically being updated to the latest ConnectWise PSA release.

On-premise Apply the 2026.1 release patches and ensure all desktop clients are up to date.

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner ConnectWise
Published Jan 16, 2026
Updated Jan 27, 2026
Reserved Jan 7, 2026
CISA Vulnrichment
Updated Jan 16, 2026
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner ConnectWise
Published Jan 16, 2026
Updated Jan 27, 2026
Exploited since n/a
EUVD-2026-2940