Vulnerability record · CVE-2025-40552 · published 28 January 2026
CVE-2025-40552: SolarWinds Web Help Desk authentication bypass
Solarwinds · Web Help Desk
SolarWinds Web Help Desk contains an authentication bypass (CWE-1390) that lets an unauthenticated actor invoke actions and methods that should require authentication. With a CVSS 3.1 score of 9.8 and full confidentiality, integrity and availability impact, this is a serious flaw in an internet-reachable help desk product.
Description
SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that if exploited, would allow a malicious actor to execute actions and methods that should be protected by authentication.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction required, high EPSS, and a public proof-of-concept make this an urgent patch target.
What it is
SolarWinds Web Help Desk contains an authentication bypass (CWE-1390) that lets an unauthenticated actor invoke actions and methods that should require authentication. With a CVSS 3.1 score of 9.8 and full confidentiality, integrity and availability impact, this is a serious flaw in an internet-reachable help desk product.
Impact
An attacker gains the ability to execute protected actions and methods without valid credentials, potentially leading to full compromise of the application and its data. The CVSS vector indicates high impact across confidentiality, integrity and availability.
Attack surface
Reachable over the network via the Web Help Desk web interface, per the CVSS vector AV:N/AC:L/PR:N/UI:N. No authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV and no ransomware usage documented, but EPSS is 0.49734 (98.8th percentile), indicating high predicted likelihood of exploitation. A public proof-of-concept script exists in the watchTowr GitHub repository, so exploitation is feasible.
What to do
- Apply the fixed release referenced in the SolarWinds Web Help Desk 2026.1 release notes or the vendor security advisory for CVE-2025-40552.
- If patching cannot be done immediately, restrict network access to the Web Help Desk interface to trusted management networks or VPN only.
- Place the Web Help Desk behind a reverse proxy or WAF with authentication and rate limiting where feasible.
- Review and rotate any credentials or secrets that may have been exposed through unauthenticated access.
- Monitor the vendor advisory and release notes for updated guidance and any follow-up CVEs.
Detection
- Review Web Help Desk access logs for requests to protected endpoints or methods that occur without a preceding successful authentication event.
- Alert on anomalous or unexpected administrative actions, configuration changes, or data exports from Web Help Desk.
- Hunt for the watchTowr PoC script user agent or request patterns in web server and proxy logs.
- Correlate Web Help Desk activity with authentication logs to identify sessions that bypass normal login flows.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2025-40552 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-40552), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.