---
title: "Critical Vulnerability: SysAid CVE-2023-47246"
url: https://daily.dev/posts/critical-vulnerability-sysaid-cve-2023-47246-ikuza97pc
source_url: https://www.huntress.com/blog/critical-vulnerability-sysaid-cve-2023-47246
type: article
source: "Huntress Blog"
published: 2026-05-31T07:42:51.986Z
updated: 2026-05-31T08:09:57.793Z
tags: ["ransomware"]
reading_time: 7
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Critical Vulnerability: SysAid CVE-2023-47246

**[Huntress Blog](https://daily.dev/sources/huntress-blog)** · 7 min read · 0 upvotes · 0 comments

## Summary

SysAid disclosed CVE-2023-47246, a critical path traversal vulnerability in their on-premise server software that allows unauthenticated attackers to upload WAR file webshells and achieve remote code execution. The flaw exists in the doPost method of the UserEntry Java class, where the accountID parameter is used unsanitized to construct file write paths. Huntress recreated a fully weaponized proof of concept by analyzing the patch diff between versions 23.3.35 and 23.3.36. Active exploitation has been attributed to TA505 (Cl0p ransomware gang), the same group behind the MOVEit Transfer attacks. Post-exploitation activity includes GraceWire malware deployment, Sophos AV evasion, and log-cleaning routines targeting SysAid and Tomcat logs. Shodan reveals up to 900 publicly accessible SysAid instances. Patching to version 23.3.36 is strongly recommended immediately.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.huntress.com/blog/critical-vulnerability-sysaid-cve-2023-47246>

## Similar posts on daily.dev

- [Max severity Ivanti Sentry vulnerability now exploited in attacks](https://daily.dev/posts/max-severity-ivanti-sentry-vulnerability-now-exploited-in-attacks-17nw2pxpe) · BleepingComputer · 0 upvotes · 0 comments
- [Apache Tomcat Path Traversal Vulnerability \(CVE-2025-55752\) Notice](https://daily.dev/posts/apache-tomcat-path-traversal-vulnerability-cve-2025-55752-notice-ayc1yqf81) · Security Boulevard · 0 upvotes · 0 comments
- [CVE-2026-10520, CVE-2026-10523 - Multiple critical vulnerabilities affecting Ivanti Sentry](https://daily.dev/posts/cve-2026-10520-cve-2026-10523---multiple-critical-vulnerabilities-affecting-ivanti-sentry-uxvwlkgex) · Rapid7 Cybersecurity Blog · 0 upvotes · 0 comments

---

Tags: [#ransomware](https://daily.dev/tags/ransomware)

[View this post on daily.dev](https://daily.dev/posts/critical-vulnerability-sysaid-cve-2023-47246-ikuza97pc)
