CRITICAL

CVE-2025-40551

Solarwinds Web Help Desk 2026-01-28 CVSS v3.1
CVSS
9.8
KEV

Description

SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication.

Summary dbcve.org

SolarWinds Web Help Desk contains an unauthenticated deserialization vulnerability that allows remote attackers to execute arbitrary commands on the host by sending specially crafted malicious data to the application.

Mitigation

Apply vendor-supplied patches immediately; if unavailable, restrict network access to the Web Help Desk interface and monitor for Indicators of Compromise.

Weakness (CWE)

CWE-502 Deserialization of Untrusted Data

EPSS Score

83.62%
Probability of exploitation in next 30 days
99.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE