/Vulnerability Library

SolarWinds Web Help Desk < 2026.1 - Unauthenticated JNDI Injection RCE

CVE-2025-40551
Verified

Description

SolarWinds Web Help Desk before version 2026.1 contains an insecure deserialization vulnerability in the jabsorb JSON-RPC library. When chained with a CSRF whitelist bypass (CVE-2025-40536), remote unauthenticated attackers can exploit JNDI injection via the Apache Xalan JNDIConnectionPool class to achieve remote code execution. The bypass involves including "/ajax/" in a query parameter to circumvent URI validation, while switching from "/ajax/" to "/wo/" endpoints bypasses payload sanitization routines.

Severity

Critical

CVSS Score

9.8

Exploit Probability

84%

Affected Product

web_help_desk

Published Date

January 28, 2026

Template Author

horizon3.ai

CVE-2025-40551.yaml
9.8Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2025-40551
CWE ID:
cwe-502

References

https://horizon3.ai/attack-research/cve-2025-40551-another-solarwinds-web-help-desk-deserialization-issue/https://www.solarwinds.com/trust-center/security-advisories/CVE-2025-40551https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_2026-1_release_notes.htmhttps://nvd.nist.gov/vuln/detail/CVE-2025-40551

Remediation Steps

Update SolarWinds Web Help Desk to version 2026.1 or later.