CVE-2025-40536
KEVmoderateUnauthenticated Security Control Bypass in SolarWinds Web Help Desk
CISA: SolarWinds Web Help Desk Security Control Bypass Vulnerability
SolarWinds Web Help Desk contains a security control bypass (CWE-693) that lets an unauthenticated, remote attacker reach functionality that should be restricted. The flaw is exploitable over the network without credentials or user interaction, which is why it carries a critical 9.8 CVSS 3.1 score. An attacker gains access to restricted features, and reporting indicates the bug has been exploited alongside related Web Help Desk flaws for unauthenticated remote code execution, with attackers installing remote-access tools such as Zoho agents and Velociraptor. Any organization running SolarWinds Web Help Desk is affected, with internet-facing help desk servers at greatest risk. CISA added the issue to its Known Exploited Vulnerabilities catalog on 2026-02-12, confirming active in-the-wild exploitation, and EPSS assigns it an 81.6% probability of exploitation within 30 days (100th percentile).
What to do: Upgrade SolarWinds Web Help Desk to the latest vendor release, which also addresses related unauthenticated RCE and authentication-bypass flaws; no fixed version number is given in this data, so follow SolarWinds' advisory for the patched release. Because the bug is under active attack, prioritize patching internet-exposed instances, restrict network access to the help desk console, and hunt for signs of compromise such as unexpected Velociraptor deployments or Zoho remote agents. Federal agencies must apply mitigations per vendor instructions and BOD 22-01 guidance within the required timeframe, or discontinue use of the product if mitigations are unavailable.
| SolarWinds Web Help Desk | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could allow an unauthenticated attacker to gain access to certain restricted functionality.
- Affected
- SolarWinds Web Help Desk
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- solarwinds
- Products
- web help desk
- Weakness
- CWE-693
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H