Amidaware

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 6
    Known Exploited: 0
    3
    Critical Level Threats
    3
    High Level Threats
    0
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-69516

    A Server-Side Template Injection (SSTI) vulnerability in the /reporting/templates/preview/ endpoint of Amidaware Tactical RMM, affecting versions equal to or earlier than v1.3.1, allows low-privileged users with Report Viewer or Report Manager permissions to achieve remote command execution on the server. This occurs due to improper sanitization of the template_md parameter, enabling direct injection of Jinja2 templates. This occurs due to misuse of the generate_html() function, the user-controlled value is inserted into `env.from_string`, a function that processes Jinja2 templates arbitrarily, making an SSTI possible.

    Last Modified: Feb 13, 2026
    Published: Jan 29, 2026

    CVE-2025-69517

    An HTML injection vulnerability in Amidaware Inc Tactical RMM v1.3.1 and earlier allows authenticated users to inject arbitrary HTML content during the creation of a new agent via the POST /api/v3/newagent/ endpoint. The agent_id parameter accepts up to 255 characters and is improperly sanitized using DOMPurify.sanitize() with the html: true option enabled, which fails to adequately filter HTML input. The injected HTML is rendered in the Tactical RMM management panel when an administrator attempts to remove or shut down the affected agent, potentially leading to client-side attacks such as UI manipulation or phishing. NOTE: the Supplier's position is that this has incorrect information.

    Last Modified: Apr 15, 2026
    Published: Jan 28, 2026

    CVE-2025-34395

    Barracuda RMM < 2025.1.1 Service Center .NET Remoting Path Traversal RCE

    Last Modified: Mar 05, 2026
    Published: Dec 10, 2025

    CVE-2025-34394

    Barracuda RMM < 2025.1.1 Service Center .NET Remoting Deserialization RCE

    Last Modified: Mar 05, 2026
    Published: Dec 10, 2025

    CVE-2025-34393

    Barracuda RMM < 2025.1.1 Service Center Insecure Reflection RCE

    Last Modified: Mar 05, 2026
    Published: Dec 10, 2025
    Items Per Page