/Vulnerability Library

SolarWinds Web Help Desk < 12.8.8 Hotfix 1 (HF1) - Security Control Bypass

CVE-2025-40536
Verified

Description

SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could allow an unauthenticated attacker to gain access to certain restricted functionality.

Severity

High

CVSS Score

8.1

Exploit Probability

74%

Affected Product

web_help_desk

Published Date

February 16, 2026

Template Author

inokii

CVE-2025-40536.yaml
8.1Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2025-40536
CWE ID:
cwe-693

References

https://www.solarwinds.com/trust-center/security-advisories/cve-2025-40536https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_2026-1_release_notes.htmhttps://horizon3.ai/attack-research/cve-2025-40551-another-solarwinds-web-help-desk-deserialization-issue/

Remediation Steps

Apply the available 12.8.8 Hotfix 1 (HF1) or upgrade to version 2026.1.