/Vulnerability Library

SolarWinds Web Help Desk - Authentication Bypass

CVE-2025-40552
Verified

Description

SolarWinds Web Help Desk contains an authentication bypass vulnerability caused by improper access control, letting attackers execute protected actions without authentication, exploit requires no special conditions.

Severity

Critical

CVSS Score

9.8

Exploit Probability

52%

Affected Product

web_help_desk

Published Date

February 26, 2026

Template Author

watchtowr, dhiyaneshdk

CVE-2025-40552.yaml
9.8Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2025-40552
CWE ID:
cwe-1390

References

https://github.com/watchtowrlabs/watchTowr-vs-SolarWinds-WebHelpDesk-CVE-2025-40552-CVE-2025-40553https://www.solarwinds.com/trust-center/security-advisories/CVE-2025-40552https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_2026-1_release_notes.htmhttps://nvd.nist.gov/vuln/detail/CVE-2025-40552

Remediation Steps

Update to the latest version of SolarWinds Web Help Desk.