Vulnerability record · CVE-2025-40554 · published 28 January 2026
CVE-2025-40554: SolarWinds Web Help Desk authentication bypass
Solarwinds · Web Help Desk
SolarWinds Web Help Desk contains an authentication bypass (CWE-1390) that lets an attacker invoke specific actions within the application without logging in. The flaw is remotely reachable with no credentials or user interaction and carries a critical CVSS score of 9.8, so unpatched, internet-facing instances are at serious risk.
Description
SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that, if exploited, could allow an attacker to invoke specific actions within Web Help Desk.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated, network-reachable authentication bypass with CVSS 9.8 and very high EPSS probability makes this an urgent patch-first issue.
What it is
SolarWinds Web Help Desk contains an authentication bypass (CWE-1390) that lets an attacker invoke specific actions within the application without logging in. The flaw is remotely reachable with no credentials or user interaction and carries a critical CVSS score of 9.8, so unpatched, internet-facing instances are at serious risk.
Impact
An unauthenticated attacker can invoke actions in Web Help Desk as if authenticated, potentially reading or modifying help desk data and configuration. The CVSS vector rates high confidentiality, integrity and availability impact, so full compromise of the application is possible.
Attack surface
Reached over the network via the Web Help Desk web interface; the CVSS vector shows no privileges required and no user interaction, so no authentication is needed. Any instance exposed to untrusted networks is directly reachable.
Exploitation
Not listed in CISA KEV and no ransomware use documented, but EPSS is 0.59156 (99th percentile), indicating a high likelihood of exploitation activity. References are limited to vendor release notes and a vendor advisory, with no public exploit details in the record.
What to do
- Apply the fixed release referenced in the SolarWinds Web Help Desk 2026.1 release notes and vendor advisory for CVE-2025-40554.
- If patching cannot be done immediately, restrict network access to Web Help Desk to trusted management networks or VPN only.
- Place the application behind a reverse proxy or WAF and block unauthenticated requests to administrative or action endpoints where feasible.
- Audit Web Help Desk accounts and configuration for unauthorized changes, and rotate credentials and secrets after any suspected exposure.
- Monitor the vendor advisory page for updated guidance and confirm the installed version against the fixed release.
Detection
- Review Web Help Desk access logs for requests to action or administrative endpoints that succeed without a preceding authenticated session.
- Alert on anomalous source IPs or user agents hitting Web Help Desk endpoints outside normal administrative patterns.
- Correlate Web Help Desk application logs with authentication logs to find actions executed with no matching login event.
- Hunt for configuration or data changes in Web Help Desk made outside change windows or by unexpected accounts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2025-40554 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-40554), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.