CVE-2025-2776
KEV PoC moderateUnauthenticated XXE in SysAid On-Prem Enables Admin Account Takeover
CISA: SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability
SysAid On-Prem, an IT service management (ITSM) platform, is vulnerable to an unauthenticated XML External Entity (XXE) flaw (CWE-611) in its Server URL processing functionality. Because the XML parser accepts attacker-controlled external entities without restriction, any remote attacker who can reach the vulnerable endpoint can trigger the flaw with no credentials and no user interaction. Successful exploitation gives the attacker arbitrary file-read primitives on the server, which can be leveraged to hijack an administrator account; public research (watchTowr) demonstrates chaining this XXE into pre-auth remote code execution, and related reporting notes SSRF and remote file access in active attacks. All SysAid On-Prem deployments running version 23.3.40 or earlier are affected. Exploitation is ongoing: CISA added CVE-2025-2776 to the Known Exploited Vulnerabilities catalog on 2025-07-22, and EPSS assigns a 64.4% probability of exploitation within 30 days.
What to do: Upgrade all SysAid On-Prem installations to a release newer than 23.3.40 per the vendor's patched advisory, applying the other recently patched SysAid fixes as well since the public PoC chains this XXE with additional flaws into pre-auth RCE. Until patched, limit internet exposure of the SysAid server and check logs for XXE/SSRF activity and unexpected administrator logins. CISA's BOD 22-01 directive requires federal agencies to apply vendor mitigations or discontinue use of the product; the PoC is public and exploitation is confirmed, so treat this as urgent.
| SysAid On-Prem | <= 23.3.40 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing functionality, allowing for administrator account takeover and file read primitives.
- Affected
- SysAid SysAid On-Prem
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- sysaid
- Products
- sysaid
- Weakness
- CWE-611
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H