CVE-2025-40552
moderateAuthentication Bypass in SolarWinds Web Help Desk
CVE-2025-40552 is a critical (CVSS 9.8) authentication bypass in SolarWinds Web Help Desk, tied to improper signature validation (CWE-1390), that allows a malicious actor to execute actions and methods that should be protected by authentication. Per the CVSS vector, it is triggered over the network (AV:N) with low attack complexity and requires no privileges or user interaction, meaning an unauthenticated remote attacker can reach the flaw directly through the product's interfaces. Successful exploitation gains the attacker the ability to perform privileged, authentication-gated operations against the help desk - such as accessing or manipulating help desk data and invoking protected application methods - with high impact to confidentiality, integrity, and availability. Any organization running SolarWinds Web Help Desk is affected, with the highest risk for deployments whose web interface is exposed to the internet. As of this data, this specific CVE is not in CISA's KEV catalog and has no known public proof-of-concept, but it was patched in the same SolarWinds advisory as companion unauthenticated RCE flaws that CISA has added to KEV as actively exploited, and EPSS assigns this CVE a roughly 50% probability of exploitation within 30 days.
What to do: Upgrade SolarWinds Web Help Desk to the patched release in the vendor's security advisory immediately, since the same advisory fixes companion unauthenticated RCE flaws that are being actively exploited in the wild. Until patched, restrict the Web Help Desk web interface to trusted networks or VPN-only access and review logs for unauthenticated calls to protected endpoints or methods. Internet-exposed instances should be treated as highest priority for patching.
| SolarWinds Web Help Desk | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that if exploited, would allow a malicious actor to execute actions and methods that should be protected by authentication.
- Vendors
- solarwinds
- Products
- web help desk
- Weakness
- CWE-1390
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H