/Vulnerability Library

SolarWinds Web Help Desk - Authentication Bypass

CVE-2025-40554
Verified

Description

SolarWinds Web Help Desk 12.8.8 HF1 and earlier contains an authentication bypass vulnerability in the WebObjects session handling. By crafting a request with a manipulated path component to an internal admin page endpoint, an unauthenticated attacker can access privileged administrative functions including authentication configuration settings, SAML/CAS setup, and API key management.

Severity

Critical

CVSS Score

9.8

Exploit Probability

61%

Affected Product

web_help_desk

Published Date

February 16, 2026

Template Author

bushi-gg

CVE-2025-40554.yaml
9.8Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2025-40554
CWE ID:
cwe-1390

References

https://www.solarwinds.com/trust-center/security-advisories/CVE-2025-40554https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_2026-1_release_notes.htmhttps://www.rapid7.com/blog/post/etr-multiple-critical-solarwinds-web-help-desk-vulnerabilities-cve-2025-40551-40552-40553-40554/https://nvd.nist.gov/vuln/detail/CVE-2025-40554

Remediation Steps

Update to Web Help Desk version 2026.1 or later.