In ConnectWise PSA versions older than 2026.1, certain session cookies were not set with the HttpOnly attribute. In some scenarios, this could allow client-side scripts access to session cookie values.
https://www.connectwise.com/company/trust/security-bulletins/2026-01-15-psa-security-fix