CVE-2025-2776

9.5 CISA KEV

SysAid · SysAid On-Prem

SysAid On-Prem contains an unauthenticated XML External Entity (XXE) vulnerability in its Server URL processing, allowing attackers to perform file reads and facilitate administrator account takeover.

Executive summary

SysAid On-Prem is vulnerable to an unauthenticated XML External Entity (XXE) attack that is currently being exploited in the wild, posing a critical risk of system compromise.

Vulnerability

This is an unauthenticated XML External Entity (XXE) vulnerability located in the Server URL processing functionality. The flaw allows unauthenticated remote attackers to read sensitive files from the server and facilitates administrator account takeover, which can be chained to achieve remote code execution.

Business impact

The exploitation of this vulnerability carries a critical business risk due to the potential for full system compromise and unauthorized access to sensitive IT infrastructure data. With a CVSS score of 9.5, the vulnerability represents an immediate threat to the confidentiality and integrity of the affected environment. Successful exploitation grants attackers the ability to exfiltrate critical information or gain administrative control over the SysAid platform, which serves as a central hub for organizational incident and asset management.

Remediation

Immediate Action: Update SysAid On-Prem to version 24.4.60 or later immediately to remediate this vulnerability.

Proactive Monitoring: Monitor server logs for suspicious XML-based requests or unusual outbound network connections initiated by the SysAid application, which may indicate attempted exploitation.

Compensating Controls: Implement strict Web Application Firewall (WAF) rules to inspect and block malicious XML payloads targeting the SysAid server endpoints until the patch can be applied.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept exists as documented in researcher write-ups and GitHub repositories.

Analyst recommendation

Given that this vulnerability is included in the CISA Known Exploited Vulnerabilities catalog and is currently being leveraged by threat actors, immediate patching is mandatory. Organizations must prioritize the upgrade to version 24.4.60 as the primary mitigation strategy to prevent unauthorized access and potential ransomware-related exploitation. Delaying this update exposes the organization to a high probability of compromise.

More SysAid CVEs

Sources

Originally found and disclosed by Sina Kheirkhah (@SinSinology), Jake Knott, with watchTowr (sponsor), per the CVE Program record.