CVE-2023-47246: SysAid Server Path Traversal Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2023-11-13. EPSS: 98.9% chance of exploitation in the next 30 days.

In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as exploited in the wild in November 2023.

Affected products

  • SysAid SysAid: before 23.3.36 (fixed in 23.3.36)

Published 2023-11-10. Last modified 2026-07-31.