CVE-2025-2776
SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 12 August 2025). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing functionality, allowing for administrator account takeover and file read primitives.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 64.40% probability · 99th percentile
- CISA KEV
- Listed 22 July 2025 · due 12 August 2025
- Weakness
- CWE-611
- Affected
- sysaid/sysaid
- Source
- disclosure@vulncheck.com
CISA notes
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. https://documentation.sysaid.com/docs/24-40-60 ; https://nvd.nist.gov/vuln/detail/CVE-2025-2776
References
- https://documentation.sysaid.com/docs/24-40-60Release Notes
- https://labs.watchtowr.com/sysowned-your-friendly-rce-support-ticket/Exploit, Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-2776US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.