Back

CRITICAL

SolarWinds Web Help Desk Authentication Bypass Vulnerability

Published Jan 28, 2026

Description

SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that if exploited, would allow a malicious actor to execute actions and methods that should be protected by authentication.

Affected products

Remediation

Vendor solution

SolarWinds recommends customers upgrade to Web Help Desk version 2026.1.

Weaknesses (1)

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner SolarWinds
Published Jan 28, 2026
Updated Feb 27, 2026
Reserved Apr 16, 2025
CISA Vulnrichment
Updated Feb 26, 2026
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner SolarWinds
Published Jan 28, 2026
Updated Feb 27, 2026
Exploited since n/a
EUVD-2025-206429