CVE-2025-40537

7.5

SolarWinds · Web Help Desk

SolarWinds Web Help Desk contains a hardcoded credentials vulnerability that may allow authenticated users to gain unauthorized access to administrative functions.

Executive summary

A hardcoded credentials vulnerability in SolarWinds Web Help Desk exposes administrative functions to unauthorized access, presenting a significant security risk.

Vulnerability

The application utilizes hardcoded credentials, which can be leveraged by an authenticated user to perform unauthorized administrative actions. This flaw is classified under CWE-798, indicating a failure to properly manage sensitive credential storage.

Business impact

Successful exploitation of this vulnerability permits unauthorized access to sensitive administrative controls within the Web Help Desk platform. Given the CVSS score of 7.5, this high-severity flaw could lead to full system compromise, data breaches, or the manipulation of help desk workflows, resulting in severe operational disruption and potential loss of data integrity.

Remediation

Immediate Action: Upgrade to Web Help Desk version 2026.1 and follow the vendor instructions to unlink the demo client from the administrative user account.

Proactive Monitoring: Audit application access logs for unusual administrative activity or successful logins from unrecognized or low-privileged user accounts.

Compensating Controls: Restrict network access to the Web Help Desk management interface to trusted internal segments or utilize a Web Application Firewall to monitor for abnormal request patterns targeting administrative endpoints.

Exploitation status

Public Exploit Available: No — there is no confirmed public exploit available.

Analyst recommendation

This vulnerability represents a high-risk security gap that requires immediate attention from IT administrators. Organizations must prioritize the upgrade to version 2026.1 and strictly follow the provided secure configuration guidance to eliminate the hardcoded credentials. Failure to remediate this issue could allow attackers to gain persistent administrative control over the application environment.

More SolarWinds CVEs

Sources

Originally found and disclosed by Jimi Sebree working with Horizon3.ai, per the CVE Program record.