← Vulnerability feed

Vulnerability record · CVE-2025-40554 · published 28 January 2026

CVE-2025-40554: SolarWinds Web Help Desk authentication bypass

Solarwinds · Web Help Desk

SolarWinds Web Help Desk contains an authentication bypass (CWE-1390) that lets an attacker invoke specific actions within the application without logging in. The flaw is remotely reachable with no credentials or user interaction and carries a critical CVSS score of 9.8, so unpatched, internet-facing instances are at serious risk.

9.8 CVSS 3.1 Critical EPSS 61% · top 0.9% CWE-1390 · CWE-1390
9.8CVSS 3.1 base score
61%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that, if exploited, could allow an attacker to invoke specific actions within Web Help Desk.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

critical priorityUnauthenticated, network-reachable authentication bypass with CVSS 9.8 and very high EPSS probability makes this an urgent patch-first issue.

What it is

SolarWinds Web Help Desk contains an authentication bypass (CWE-1390) that lets an attacker invoke specific actions within the application without logging in. The flaw is remotely reachable with no credentials or user interaction and carries a critical CVSS score of 9.8, so unpatched, internet-facing instances are at serious risk.

Impact

An unauthenticated attacker can invoke actions in Web Help Desk as if authenticated, potentially reading or modifying help desk data and configuration. The CVSS vector rates high confidentiality, integrity and availability impact, so full compromise of the application is possible.

Attack surface

Reached over the network via the Web Help Desk web interface; the CVSS vector shows no privileges required and no user interaction, so no authentication is needed. Any instance exposed to untrusted networks is directly reachable.

Exploitation

Not listed in CISA KEV and no ransomware use documented, but EPSS is 0.59156 (99th percentile), indicating a high likelihood of exploitation activity. References are limited to vendor release notes and a vendor advisory, with no public exploit details in the record.

What to do

  • Apply the fixed release referenced in the SolarWinds Web Help Desk 2026.1 release notes and vendor advisory for CVE-2025-40554.
  • If patching cannot be done immediately, restrict network access to Web Help Desk to trusted management networks or VPN only.
  • Place the application behind a reverse proxy or WAF and block unauthenticated requests to administrative or action endpoints where feasible.
  • Audit Web Help Desk accounts and configuration for unauthorized changes, and rotate credentials and secrets after any suspected exposure.
  • Monitor the vendor advisory page for updated guidance and confirm the installed version against the fixed release.

Detection

  • Review Web Help Desk access logs for requests to action or administrative endpoints that succeed without a preceding authenticated session.
  • Alert on anomalous source IPs or user agents hitting Web Help Desk endpoints outside normal administrative patterns.
  • Correlate Web Help Desk application logs with authentication logs to find actions executed with no matching login event.
  • Hunt for configuration or data changes in Web Help Desk made outside change windows or by unexpected accounts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-40554 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-40551SolarWinds Web Help Desk unauthenticated deserialization RCESolarWinds Web Help Desk contains an untrusted data deserialization flaw (CWE-502) that can lead to remote code execution, allowing an attacker to ru…KEVEPSS 84%analysed9.8CVE-2025-40536SolarWinds Web Help Desk security control bypass allows unauthenticated accessSolarWinds Web Help Desk contains a security control bypass (CWE-693) that lets an unauthenticated attacker reach restricted functionality. It is rat…KEVEPSS 74%analysed9.8CVE-2025-26399SolarWinds Web Help Desk unauthenticated deserialization RCESolarWinds Web Help Desk contains an unauthenticated deserialization flaw in the AjaxProxy component that allows remote code execution on the host. I…KEVEPSS 90%analysed9.8CVE-2024-28986SolarWinds Web Help Desk Java deserialization remote code executionSolarWinds Web Help Desk contains a Java deserialization flaw (CWE-502) that allows remote code execution on the host. The vendor originally reported…KEVEPSS 85%analysed9.1CVE-2024-28987SolarWinds Web Help Desk hardcoded credential flawSolarWinds Web Help Desk contains a hardcoded credential vulnerability (CWE-798) that lets a remote, unauthenticated attacker reach internal function…KEVEPSS 93%analysed9.8CVE-2026-28323Solarwinds web help desk improper authentication vulnerabilitySolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2.0 authentication method to b…EPSS 1.0%9.8CVE-2025-40552SolarWinds Web Help Desk authentication bypassSolarWinds Web Help Desk contains an authentication bypass (CWE-1390) that lets an unauthenticated actor invoke actions and methods that should requi…EPSS 52%analysed9.8CVE-2025-40553SolarWinds Web Help Desk unauthenticated deserialization RCESolarWinds Web Help Desk is affected by an untrusted data deserialization flaw (CWE-502) that can lead to remote code execution. The vulnerability is…EPSS 68%analysed

Source: NIST National Vulnerability Database (record CVE-2025-40554), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.