Skip to content
COOEY

FAIL › dossier

SysAid On-Prem

PRODUCT

· dossier confidence 80%

SysAid is a UK-based ITSM software provider with a critical security track record marked by two high-severity RCE vulnerabilities in July 2025 that enabled admin takeover and file reads.

PROFILE
CategoryITSM SoftwareWhat they doSysAid provides IT service management (ITSM) software used by IT teams to manage service requests, incidents, and IT asset management tools, available in cloud and on-premises deployments.Founded2013SizeUnknownOwnershipPrivate Websitehttps://sysaid.com ↗
SECURITY POSTURE

High-risk due to repeated critical RCE vulnerabilities in 2025, indicating systemic issues with XML parsing and administrative access controls.

Notable failures
  • CVE-2025-2776: XML entity reference vulnerability enabling admin takeover
  • CVE-2025-2775: XML External Entity Reference allowing file reads
  • 2025-07-22: Admin takeover via XML parsing flaw
Patterns: Repeated XML parsing vulnerabilities; High-severity RCE in 2025
FAILURE HISTORY · 2
DATEEVENTSEVSUMMARY
2025-07-22 CVE-2025-2776 high SysAid On-Prem suffered XML entity reference vulnerability leading to admin takeover and file reads
2025-07-22 CVE-2025-2775 high SysAid On-Prem allowed XML External Entity Reference, enabling admin takeover and file reads
Open questions: Company founding date and headquarters location · Company size and ownership structure · Website URL
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-01 03:45:55.770439+00:00