SolarWinds Web Help Desk < 12.8.7 - AjaxProxy Deserialization RCE
CVE-2025-26399
Verified
Description
SolarWinds Web Help Desk contains an unauthenticated AjaxProxy deserialization remote code execution vulnerability, letting attackers run commands on the host machine without authentication, exploit requires no special privileges.
Severity
Critical
CVSS Score
9.8
Exploit Probability
90%
Affected Product
web_help_desk
Published Date
August 14, 2026
Template Author
popy21
CVE-2025-26399.yaml
9.8Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2025-26399
CWE ID:
cwe-502
References
https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_12-8-7-hotfix-1_release_notes.htmhttps://www.solarwinds.com/trust-center/security-advisories/CVE-2025-26399https://nvd.nist.gov/vuln/detail/CVE-2025-26399https://labs.watchtowr.com/buy-a-help-desk-bundle-a-remote-access-solution-solarwinds-web-help-desk-pre-auth-rce-chain-s/https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-26399
Remediation Steps
Update to the latest version that addresses this vulnerability.