Description
SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could allow an unauthenticated attacker to gain access to certain restricted functionality.
Problem types
CWE-693 Protection Mechanism Failure
Product status
12.8.8 HF1 and below
Credits
Jimi Sebree working with Horizon3.ai
References
www.cisa.gov/...erabilities-catalog?field_cve=CVE-2025-40536
www.huntress.com/...-solarwinds-web-help-desk-cve-2025-26399
www.solarwinds.com/...ter/security-advisories/CVE-2025-40536
documentation.solarwinds.com/...whd_2026-1_release_notes.htm