/Vulnerability Library

SolarWinds Web Help Desk < 12.8.7 - AjaxProxy Deserialization RCE

CVE-2025-26399
Verified

Description

SolarWinds Web Help Desk contains an unauthenticated AjaxProxy deserialization remote code execution vulnerability, letting attackers run commands on the host machine without authentication, exploit requires no special privileges.

Severity

Critical

CVSS Score

9.8

Exploit Probability

90%

Affected Product

web_help_desk

Published Date

August 14, 2026

Template Author

popy21

CVE-2025-26399.yaml
9.8Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2025-26399
CWE ID:
cwe-502

References

https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_12-8-7-hotfix-1_release_notes.htmhttps://www.solarwinds.com/trust-center/security-advisories/CVE-2025-26399https://nvd.nist.gov/vuln/detail/CVE-2025-26399https://labs.watchtowr.com/buy-a-help-desk-bundle-a-remote-access-solution-solarwinds-web-help-desk-pre-auth-rce-chain-s/https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-26399

Remediation Steps

Update to the latest version that addresses this vulnerability.