SolarWinds Web Help Desk - Authentication Bypass
CVE-2025-40552
Verified
Description
SolarWinds Web Help Desk contains an authentication bypass vulnerability caused by improper access control, letting attackers execute protected actions without authentication, exploit requires no special conditions.
Severity
Critical
CVSS Score
9.8
Exploit Probability
52%
Affected Product
web_help_desk
Published Date
February 26, 2026
Template Author
watchtowr, dhiyaneshdk
CVE-2025-40552.yaml
9.8Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2025-40552
CWE ID:
cwe-1390
References
https://github.com/watchtowrlabs/watchTowr-vs-SolarWinds-WebHelpDesk-CVE-2025-40552-CVE-2025-40553https://www.solarwinds.com/trust-center/security-advisories/CVE-2025-40552https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_2026-1_release_notes.htmhttps://nvd.nist.gov/vuln/detail/CVE-2025-40552
Remediation Steps
Update to the latest version of SolarWinds Web Help Desk.