CRITICAL
SolarWinds Web Help Desk Authentication Bypass Vulnerability
Published Jan 28, 2026
9.8
CRITICALCVSS 3.1
EPSS 52.00%
Description
SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that if exploited, would allow a malicious actor to execute actions and methods that should be protected by authentication.
Affected products
-
- Version 12.8.8 HF1 and belowStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| SolarWinds | Web Help Desk | affected |
|
- < 2026.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
SolarWinds recommends customers upgrade to Web Help Desk version 2026.1.
Weaknesses (1)
References (4)
- https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_2026-1_release_notes.htm Release Notes
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-206429 Advisory
- https://github.com/watchtowrlabs/watchTowr-vs-SolarWinds-WebHelpDesk-CVE-2025-40552-CVE-2025-40553/blob/main/watchTowr-vs-SolarWinds-WebHelpDesk-CVE-2025-40552-CVE-2025-40553.py exploit
- https://www.solarwinds.com/trust-center/security-advisories/CVE-2025-40552 vendor-advisorypatchVendor Advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner SolarWinds
Published Jan 28, 2026
Updated Feb 27, 2026
Reserved Apr 16, 2025
Link CVE-2025-40552
CISA Vulnrichment
Updated Feb 26, 2026
ENISA EUVD
EUVD-2025-206429 Assigner SolarWinds
Published Jan 28, 2026
Updated Feb 27, 2026
Exploited since n/a
Link EUVD-2025-206429