PT-2025-28899 · Connectwise · Connectwise Psa

Michael Newton

·

Published

2025-07-09

·

Updated

2025-08-20

·

CVE-2025-7204

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions: ConnectWise PSA versions prior to 2025.9
Description: A vulnerability exists where authenticated users could gain access to sensitive user information. Specific API requests return an overly verbose user object, which includes encrypted password hashes for other users. An attacker or privileged user could use these exposed hashes to conduct offline brute-force or dictionary attacks, potentially leading to credential compromise and privilege escalation within the system.
Recommendations: Update ConnectWise PSA to version 2025.9 or later.

Fix

LPE

Weakness Enumeration

Related Identifiers

BDU:2026-00085
CVE-2025-7204

Affected Products

Connectwise Psa