CVE-2025-69516Disclosure(amidaware / tactical_rmm)

LOWCVSS 8.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A Server-Side Template Injection (SSTI) vulnerability in the /reporting/templates/preview/ endpoint of Amidaware Tactical RMM, affecting versions equal to or earlier than v1.3.1, allows low-privileged users with Report Viewer or Report Manager permissions to achieve remote command execution on the server. This occurs due to improper sanitization of the template_md parameter, enabling direct injection of Jinja2 templates. This occurs due to misuse of the generate_html() function, the user-controlled value is inserted into `env.from_string`, a function that processes Jinja2 templates arbitrarily, making an SSTI possible.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1336

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • tactical_rmm

Threat summary

  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-01-29); latest day: 2
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
tactical_rmm

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-01-29: 3Mentions · 2026-01-30: 2Technical Details · 2026-01-29: 3Technical Details · 2026-01-30: 101-2901-30
Signal classification2 categories
Disclosure
480.0%
General
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-01-293
Disclosure3
2026-01-302
Disclosure1General1
Full discourse5 posts
  • CVE@CVEnew
    Disclosure

    CVE-2025-69516 A Server-Side Template Injection (SSTI) vulnerability in the /reporting/templates/preview/ endpoint of Amidaware Tactical RMM, affecting versions equal to or earlier … https://www.cve.org/CVERecord?id=CVE-2025-69516

    Post summary

    The post details an SSTI vulnerability in Amidaware Tactical RMM, providing technical specifics but no proof‑of‑concept, exploit code, active exploitation evidence, or patch information.

    01010239
    56.5K followersView on X
  • Sniss7k@SNISS8
    General

    @bbwriteups Is the CVE-2025-69516! Not the CVE-2025-69517

    Post summary

    The tweet merely distinguishes between CVE-2025-69516 and CVE-2025-69517 without providing further technical or operational details.

    00010104
    50 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2025-69516 - High A Server-Side Template Injection (SSTI) vulnerability in the /reporting/templates/preview/ endpoint of Amidaware Tactical RMM, affecting versions equal to or earlier than v1.3.1, allows low-p... https://www.thehackerwire.com/vulnerability/CVE-2025-69516/ https://t.co/t9kHOhD731

    Post summary

    The post announces a high‑severity SSTI vulnerability in Amidaware Tactical RMM’s preview endpoint (v1.3.1 and earlier), with no PoC, exploit, or patch information provided.

    00010135
    113 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-69516 Server-Side Template Injection in Tactical RMM v1.3.1 Enables Remote Command Execution https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-69516

    Post summary

    The text announces a server‑side template injection vulnerability in Tactical RMM v1.3.1 that enables remote command execution.

    0001095
    4.0K followersView on X
  • Sniss7k@SNISS8
    Disclosure

    My 2 new CVES!! https://www.cve.org/CVERecord?id=CVE-2025-69516 https://www.cve.org/CVERecord?id=CVE-2025-69517 The first one allows RCE using SSTI and the second one is a html injection storage! Both on TacticalRMM Thanks for my teammates: m0unt ( Ntgabriel) and 0xL1zard

    Post summary

    Two new CVEs for TacticalRMM are disclosed: one permits RCE via Server-Side Template Injection, and the other allows HTML injection storage.

    00000137
    50 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appamidawaretactical_rmm---

Explore more