Unrated severityNVD Advisory· Published Jan 28, 2026· Updated Feb 27, 2026
SolarWinds Web Help Desk Authentication Bypass Vulnerability
CVE-2025-40552
Description
SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that if exploited, would allow a malicious actor to execute actions and methods that should be protected by authentication.
Affected products
2- SolarWinds/Web Help Deskv5Range: 12.8.8 HF1 and below
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
1- Buy A Help Desk, Bundle A Remote Access Solution? (SolarWinds Web Help Desk Pre-Auth RCE Chain(s))watchTowr Labs · Feb 25, 2026