SolarWinds Web Help Desk < 2026.1 - Unauthenticated JNDI Injection RCE
CVE-2025-40551
Verified
Description
SolarWinds Web Help Desk before version 2026.1 contains an insecure deserialization vulnerability in the jabsorb JSON-RPC library. When chained with a CSRF whitelist bypass (CVE-2025-40536), remote unauthenticated attackers can exploit JNDI injection via the Apache Xalan JNDIConnectionPool class to achieve remote code execution. The bypass involves including "/ajax/" in a query parameter to circumvent URI validation, while switching from "/ajax/" to "/wo/" endpoints bypasses payload sanitization routines.
Severity
Critical
CVSS Score
9.8
Exploit Probability
84%
Affected Product
web_help_desk
Published Date
January 28, 2026
Template Author
horizon3.ai
CVE-2025-40551.yaml
9.8Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2025-40551
CWE ID:
cwe-502
References
https://horizon3.ai/attack-research/cve-2025-40551-another-solarwinds-web-help-desk-deserialization-issue/https://www.solarwinds.com/trust-center/security-advisories/CVE-2025-40551https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_2026-1_release_notes.htmhttps://nvd.nist.gov/vuln/detail/CVE-2025-40551
Remediation Steps
Update SolarWinds Web Help Desk to version 2026.1 or later.