← back
CVE-2025-40554criticalobserved exploitationCWE-1390

SolarWinds Web Help Desk Authentication Bypass Vulnerability

97Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actcvss 9.8epss 57%
from disclosure to weapon1 days
Published on NVDJan 28
1st PoC+1d
VulnCheck+93d
exploitation probability
57%top 1% of all CVEs
observed exploitation
yesVulnCheck
3 public exploit(s)
In short

SolarWinds Web Help Desk has a flaw that lets attackers skip authentication and perform actions they shouldn't be able to do. This is critical because it gives unauthorized access to a system meant to manage support tickets and user data.

Technical detail

An authentication bypass vulnerability in SolarWinds Web Help Desk allows unauthenticated attackers to invoke arbitrary actions without valid credentials. The vulnerability bypasses the authentication mechanism entirely, granting unauthorized access to sensitive functions and data within the application.

Summary generated and translated by AI from the official description.
SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that, if exploited, could allow an attacker to invoke specific actions within Web Help Desk.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.