CVE-2025-40554
moderateAuthentication Bypass in SolarWinds Web Help Desk
CVE-2025-40554 is an authentication bypass (CWE-1390, missing authentication) in SolarWinds Web Help Desk, scored 9.8 Critical because it is reachable over the network with no privileges, low attack complexity, and high confidentiality/integrity/availability impact. An unauthenticated attacker can send requests that invoke specific actions within Web Help Desk without valid credentials, bypassing the product's access controls. It affects organizations running the on-premises SolarWinds Web Help Desk ticketing system, a product typically deployed by enterprises and MSPs. The flaw was assigned by SolarWinds' PSIRT and fixed as part of a batch of four critical Web Help Desk issues (unauthenticated RCE plus auth bypass); per the provided data there is no public PoC and this specific CVE is not yet in CISA KEV, though sibling Web Help Desk RCE flaws from the same advisory are actively exploited and have been added to the KEV Catalog, and EPSS assigns this CVE a 58.4% probability of exploitation within 30 days.
What to do: Upgrade Web Help Desk to the patched release identified in SolarWinds' advisory covering the four critical flaws (unauthenticated RCE and auth bypass), since exact fixed build numbers are not given in this data set. Until patched, restrict access to the Web Help Desk web interface to trusted networks and review authentication logs for unauthenticated requests invoking product actions. Note that related Web Help Desk RCE flaws are in CISA KEV and being actively exploited, so treat unpatched instances as at high risk.
| SolarWinds Web Help Desk | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that, if exploited, could allow an attacker to invoke specific actions within Web Help Desk.
- Vendors
- solarwinds
- Products
- web help desk
- Weakness
- CWE-1390
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H