ZeroHour

CVE-2025-2776

KEV PoC moderate

Unauthenticated XXE in SysAid On-Prem Enables Admin Account Takeover

CISA: SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability

CVSS 3.1
9.8 critical
EPSS
64%p99
Published
()
KEV added
AI analysis

SysAid On-Prem, an IT service management (ITSM) platform, is vulnerable to an unauthenticated XML External Entity (XXE) flaw (CWE-611) in its Server URL processing functionality. Because the XML parser accepts attacker-controlled external entities without restriction, any remote attacker who can reach the vulnerable endpoint can trigger the flaw with no credentials and no user interaction. Successful exploitation gives the attacker arbitrary file-read primitives on the server, which can be leveraged to hijack an administrator account; public research (watchTowr) demonstrates chaining this XXE into pre-auth remote code execution, and related reporting notes SSRF and remote file access in active attacks. All SysAid On-Prem deployments running version 23.3.40 or earlier are affected. Exploitation is ongoing: CISA added CVE-2025-2776 to the Known Exploited Vulnerabilities catalog on 2025-07-22, and EPSS assigns a 64.4% probability of exploitation within 30 days.

What to do: Upgrade all SysAid On-Prem installations to a release newer than 23.3.40 per the vendor's patched advisory, applying the other recently patched SysAid fixes as well since the public PoC chains this XXE with additional flaws into pre-auth RCE. Until patched, limit internet exposure of the SysAid server and check logs for XXE/SSRF activity and unexpected administrator logins. CISA's BOD 22-01 directive requires federal agencies to apply vendor mitigations or discontinue use of the product; the PoC is public and exploitation is confirmed, so treat this as urgent.

Affected
SysAid On-Prem<= 23.3.40
Estimated exposure
moderate≈2,000–10,000 internet-exposed SysAid On-Prem instances (thousands of customer organizations, many running the helpdesk portal on public endpoints) — SysAid's installed base is thousands of organizations and, as in the 2023 SysAid exploitation campaign, on-prem ITSM servers are commonly left internet-accessible; public scan-style exposure for self-hosted helpdesk products typically runs…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing functionality, allowing for administrator account takeover and file read primitives.

CISA Known Exploited Vulnerability
Affected
SysAid SysAid On-Prem
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
sysaid
Products
sysaid
Weakness
CWE-611
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news