← back
CVE-2025-40552criticalCWE-1390

SolarWinds Web Help Desk Authentication Bypass Vulnerability

75Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendcvss 9.8epss 50%
from disclosure to weapon16 days
Published on NVDJan 28
1st PoC+16d
exploitation probability
50%top 1% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
In short

SolarWinds Web Help Desk has a security flaw that lets attackers bypass login requirements and access protected features without valid credentials. This is critical because it allows unauthorized users to perform any action on the system.

Technical detail

An authentication bypass vulnerability in SolarWinds Web Help Desk permits unauthenticated attackers to invoke protected methods and execute administrative actions, circumventing access controls. The vulnerability enables direct exploitation without credential requirements, resulting in complete compromise of system functionality and data access.

Summary generated and translated by AI from the official description.
SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that if exploited, would allow a malicious actor to execute actions and methods that should be protected by authentication.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.