← Vulnerability feed

Vulnerability record · CVE-2025-40552 · published 28 January 2026

CVE-2025-40552: SolarWinds Web Help Desk authentication bypass

Solarwinds · Web Help Desk

SolarWinds Web Help Desk contains an authentication bypass (CWE-1390) that lets an unauthenticated actor invoke actions and methods that should require authentication. With a CVSS 3.1 score of 9.8 and full confidentiality, integrity and availability impact, this is a serious flaw in an internet-reachable help desk product.

9.8 CVSS 3.1 Critical EPSS 52% · top 1.1% CWE-1390 · CWE-1390
9.8CVSS 3.1 base score
52%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that if exploited, would allow a malicious actor to execute actions and methods that should be protected by authentication.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or user interaction required, high EPSS, and a public proof-of-concept make this an urgent patch target.

What it is

SolarWinds Web Help Desk contains an authentication bypass (CWE-1390) that lets an unauthenticated actor invoke actions and methods that should require authentication. With a CVSS 3.1 score of 9.8 and full confidentiality, integrity and availability impact, this is a serious flaw in an internet-reachable help desk product.

Impact

An attacker gains the ability to execute protected actions and methods without valid credentials, potentially leading to full compromise of the application and its data. The CVSS vector indicates high impact across confidentiality, integrity and availability.

Attack surface

Reachable over the network via the Web Help Desk web interface, per the CVSS vector AV:N/AC:L/PR:N/UI:N. No authentication and no user interaction are required.

Exploitation

Not listed in CISA KEV and no ransomware usage documented, but EPSS is 0.49734 (98.8th percentile), indicating high predicted likelihood of exploitation. A public proof-of-concept script exists in the watchTowr GitHub repository, so exploitation is feasible.

What to do

  • Apply the fixed release referenced in the SolarWinds Web Help Desk 2026.1 release notes or the vendor security advisory for CVE-2025-40552.
  • If patching cannot be done immediately, restrict network access to the Web Help Desk interface to trusted management networks or VPN only.
  • Place the Web Help Desk behind a reverse proxy or WAF with authentication and rate limiting where feasible.
  • Review and rotate any credentials or secrets that may have been exposed through unauthenticated access.
  • Monitor the vendor advisory and release notes for updated guidance and any follow-up CVEs.

Detection

  • Review Web Help Desk access logs for requests to protected endpoints or methods that occur without a preceding successful authentication event.
  • Alert on anomalous or unexpected administrative actions, configuration changes, or data exports from Web Help Desk.
  • Hunt for the watchTowr PoC script user agent or request patterns in web server and proxy logs.
  • Correlate Web Help Desk activity with authentication logs to identify sessions that bypass normal login flows.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-40552 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-40551SolarWinds Web Help Desk unauthenticated deserialization RCESolarWinds Web Help Desk contains an untrusted data deserialization flaw (CWE-502) that can lead to remote code execution, allowing an attacker to ru…KEVEPSS 84%analysed9.8CVE-2025-40536SolarWinds Web Help Desk security control bypass allows unauthenticated accessSolarWinds Web Help Desk contains a security control bypass (CWE-693) that lets an unauthenticated attacker reach restricted functionality. It is rat…KEVEPSS 74%analysed9.8CVE-2025-26399SolarWinds Web Help Desk unauthenticated deserialization RCESolarWinds Web Help Desk contains an unauthenticated deserialization flaw in the AjaxProxy component that allows remote code execution on the host. I…KEVEPSS 90%analysed9.8CVE-2024-28986SolarWinds Web Help Desk Java deserialization remote code executionSolarWinds Web Help Desk contains a Java deserialization flaw (CWE-502) that allows remote code execution on the host. The vendor originally reported…KEVEPSS 85%analysed9.1CVE-2024-28987SolarWinds Web Help Desk hardcoded credential flawSolarWinds Web Help Desk contains a hardcoded credential vulnerability (CWE-798) that lets a remote, unauthenticated attacker reach internal function…KEVEPSS 93%analysed9.8CVE-2026-28323Solarwinds web help desk improper authentication vulnerabilitySolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2.0 authentication method to b…EPSS 1.0%9.8CVE-2025-40553SolarWinds Web Help Desk unauthenticated deserialization RCESolarWinds Web Help Desk is affected by an untrusted data deserialization flaw (CWE-502) that can lead to remote code execution. The vulnerability is…EPSS 68%analysed9.8CVE-2025-40554SolarWinds Web Help Desk authentication bypassSolarWinds Web Help Desk contains an authentication bypass (CWE-1390) that lets an attacker invoke specific actions within the application without lo…EPSS 61%analysed

Source: NIST National Vulnerability Database (record CVE-2025-40552), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.