SolarWinds Web Help Desk - Authentication Bypass
CVE-2025-40554
Verified
Description
SolarWinds Web Help Desk 12.8.8 HF1 and earlier contains an authentication bypass vulnerability in the WebObjects session handling. By crafting a request with a manipulated path component to an internal admin page endpoint, an unauthenticated attacker can access privileged administrative functions including authentication configuration settings, SAML/CAS setup, and API key management.
Severity
Critical
CVSS Score
9.8
Exploit Probability
61%
Affected Product
web_help_desk
Published Date
February 16, 2026
Template Author
bushi-gg
CVE-2025-40554.yaml
9.8Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2025-40554
CWE ID:
cwe-1390
References
https://www.solarwinds.com/trust-center/security-advisories/CVE-2025-40554https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_2026-1_release_notes.htmhttps://www.rapid7.com/blog/post/etr-multiple-critical-solarwinds-web-help-desk-vulnerabilities-cve-2025-40551-40552-40553-40554/https://nvd.nist.gov/vuln/detail/CVE-2025-40554
Remediation Steps
Update to Web Help Desk version 2026.1 or later.