CVE-2025-40536

9.5 CISA KEV

SolarWinds · Web Help Desk

SolarWinds Web Help Desk contains a security control bypass vulnerability that allows unauthenticated attackers to access restricted system functionality.

Executive summary

This critical security control bypass vulnerability in SolarWinds Web Help Desk is currently being exploited in the wild and requires immediate remediation.

Vulnerability

This flaw involves a protection mechanism failure (CWE-693) that allows an unauthenticated attacker to bypass request filters. By circumventing these controls, unauthorized parties can gain access to restricted functionality within the application.

Business impact

With a CVSS score of 9.5, this vulnerability represents a critical risk to organizational security. Successful exploitation could lead to unauthorized access to sensitive help desk data, potential configuration changes, or further compromise of the internal network, posing a significant risk of data exfiltration and operational disruption.

Remediation

Immediate Action: Upgrade all instances of SolarWinds Web Help Desk to version 2026.1 immediately to resolve the underlying protection mechanism failure.

Proactive Monitoring: Review web server and application logs for suspicious, high-frequency requests targeting administrative endpoints or unusual patterns that suggest attempts to bypass authentication filters.

Compensating Controls: Deploy Web Application Firewall (WAF) rules designed to filter or block unauthorized requests to internal-only endpoints, though these should only be considered temporary measures until the software is patched.

Exploitation status

Public Exploit Available: Yes, a Metasploit module and Nuclei template are available.

Analyst recommendation

Given the active exploitation and the critical nature of this security control bypass, administrators must prioritize this update above all other maintenance tasks. Ensure that all SolarWinds Web Help Desk deployments are patched to version 2026.1 without delay, and verify that no unauthorized access has occurred by reviewing audit logs from the date of the vulnerability disclosure.

More SolarWinds CVEs

Sources

Originally found and disclosed by Jimi Sebree working with Horizon3.ai, per the CVE Program record.