CRITICAL

CVE-2025-26399

Solarwinds Web Help Desk 2025-09-23 CVSS v3.1
CVSS
9.8
KEV

Description

SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote code execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. This vulnerability is a patch bypass of CVE-2024-28988, which in turn is a patch bypass of CVE-2024-28986.

Summary dbcve.org

SolarWinds Web Help Desk contains an unauthenticated deserialization remote code execution vulnerability in its AjaxProxy component. Attackers can exploit this to execute arbitrary commands on the host machine without any authentication credentials. This CVE is a patch bypass of CVE-2024-28988, which itself bypassed CVE-2024-28986, indicating the vulnerability persists across multiple attempted fixes.

Mitigation

Apply the vendor-supplied patch for CVE-2025-26399 immediately, as the CVSS 9.8 rating and unauthenticated attack vector present critical risk. As an interim control, restrict network access to the Web Help Desk service or disable the AjaxProxy functionality if not required.

Patch Commit

Weakness (CWE)

CWE-502 Deserialization of Untrusted Data

EPSS Score

89.5%
Probability of exploitation in next 30 days
99.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE