← Vulnerability feed

Vulnerability record · CVE-2015-6922 · published 17 February 2020

CVE-2015-6922: Kaseya VSA authentication bypass allows admin account creation and code execution

Kaseya · Virtual System Administrator

Kaseya Virtual System Administrator (VSA) versions 7.x, 8.x, 9.0 and 9.1 before their respective fixed builds fail to properly require authentication on certain endpoints. A remote attacker can bypass authentication to add an administrative account via LocalAuth/setAccount.aspx or write and execute arbitrary files via the PathData parameter to ConfigTab/uploader.aspx. Because VSA is a remote management platform, compromise gives an attacker broad control over managed endpoints.

9.8 CVSS 3.1 Critical EPSS 82% · top 0.4% CWE-287 · Improper authentication
9.8CVSS 3.1 base score, v2 7.5
82%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.33, 8.x before 8.0.0.23, 9.0 before 9.0.0.19, and 9.1 before 9.1.0.9 does not properly require authentication, which allows remote attackers to bypass authentication and (1) add an administrative account via crafted request to LocalAuth/setAccount.aspx or (2) write to and execute arbitrary files via a full pathname in the PathData parameter to ConfigTab/uploader.aspx.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 9.8 unauthenticated remote authentication bypass with public exploit code and very high EPSS on an internet-facing management platform.

What it is

Kaseya Virtual System Administrator (VSA) versions 7.x, 8.x, 9.0 and 9.1 before their respective fixed builds fail to properly require authentication on certain endpoints. A remote attacker can bypass authentication to add an administrative account via LocalAuth/setAccount.aspx or write and execute arbitrary files via the PathData parameter to ConfigTab/uploader.aspx. Because VSA is a remote management platform, compromise gives an attacker broad control over managed endpoints.

Impact

An unauthenticated attacker gains administrative access to the VSA instance and can execute arbitrary code on the server, then leverage VSA's management reach to control managed systems.

Attack surface

Reachable over the network via HTTP requests to the VSA web interface; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).

Exploitation

Public exploit code is referenced (Packet Storm, Exploit-DB) and EPSS is high at 0.821 (99.6th percentile), though the CVE is not listed in CISA KEV.

What to do

  • Upgrade Kaseya VSA to 7.0.0.33, 8.0.0.23, 9.0.0.19, 9.1.0.9 or later fixed builds.
  • Restrict network access to the VSA web interface to trusted management networks or VPN only.
  • Audit VSA for unexpected administrative accounts and remove any unauthorized ones.
  • Review and harden file upload paths and permissions on the VSA server.
  • Monitor vendor advisory channels for updated guidance since the linked Kaseya advisory is broken.

Detection

  • Monitor web logs for requests to LocalAuth/setAccount.aspx and ConfigTab/uploader.aspx, especially from untrusted sources.
  • Alert on creation of new administrative accounts in VSA outside change windows.
  • Look for unexpected file writes or process execution originating from the VSA web server.
  • Correlate VSA access with outbound management actions to endpoints that were not initiated by known admins.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2015-6922 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-20753Kaseya VSA RMM unauthenticated remote code executionKaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell payload…KEVEPSS 29%analysed8.8CVE-2015-6589Kaseya virtual system administrator path traversal vulnerabilityDirectory traversal vulnerability in Kaseya Virtual System Administrator (VSA) 7.0.0.0 before 7.0.0.33, 8..0.0.0 before 8.0.0.23, 9.0.0.0 before 9.0.…EPSS 14%7.5CVE-2019-15506Kaseya virtual system administrator missing authentication for critical function vulnerabilityAn issue was discovered in Kaseya Virtual System Administrator (VSA) through 9.4.0.37. It has a critical information disclosure vulnerability. An una…EPSS 1.8%7.4CVE-2017-12410Kaseya virtual system administrator race condition vulnerabilityIt is possible to exploit a Time of Check & Time of Use (TOCTOU) vulnerability by winning a race condition when Kaseya Virtual System Administrator a…EPSS 0.25%4.3CVE-2015-2863Kaseya virtual system administrator vulnerabilityOpen redirect vulnerability in Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.29, 8.x before 8.0.0.18, 9.0 before 9.0.0.14, and 9.1 befor…EPSS 10%4.0CVE-2015-2862Kaseya virtual system administrator path traversal vulnerabilityDirectory traversal vulnerability in Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.29, 8.x before 8.0.0.18, 9.0 before 9.0.0.14, and 9.1…EPSS 9.5%1.7CVE-2014-2926Kaseya virtual system administrator vulnerabilitykapfa.sys in Kaseya Virtual System Administrator (VSA) 6.5 before 6.5.0.17 and 7.0 before 7.0.0.16 allows local users to cause a denial of service (N…EPSS 0.33%7.5CVE-2026-42018JFrog Artifactory improper authentication leaks anonymous tokenJFrog Artifactory can return an internal anonymous-user token to an unauthenticated caller even when anonymous access is disabled. Because the token …KEVEPSS 9.8%analysed

Source: NIST National Vulnerability Database (record CVE-2015-6922), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.