Medium severity5.3NVD Advisory· Published Aug 26, 2021· Updated Jun 17, 2026
CVE-2021-32076
CVE-2021-32076
Description
Access Restriction Bypass via referrer spoof was discovered in SolarWinds Web Help Desk 12.7.2. An attacker can access the 'Web Help Desk Getting Started Wizard', especially the admin account creation page, from a non-privileged IP address network range or loopback address by intercepting the HTTP request and changing the referrer from the public IP address to the loopback.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: = 12.7.2
- SolarWinds/Web Help Deskv5Range: unspecified
Patches
Vulnerability mechanics
References
2- exchange.xforce.ibmcloud.com/vulnerabilities/208278nvdThird Party AdvisoryVDB Entry
- www.solarwinds.com/trust-center/security-advisories/cve-2021-32076nvdVendor Advisory
News mentions
0No linked articles in our index yet.