Critical severity9.8NVD Advisory· Published Jan 28, 2026· Updated Jun 17, 2026
CVE-2025-40552
CVE-2025-40552
Description
SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that if exploited, would allow a malicious actor to execute actions and methods that should be protected by authentication.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:solarwinds:web_help_desk:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:solarwinds:web_help_desk:*:*:*:*:*:*:*:*range: <2026.1
- (no CPE)
- (no CPE)range: 12.8.8 HF1 and below
Patches
Vulnerability mechanics
References
3- www.solarwinds.com/trust-center/security-advisories/CVE-2025-40552nvdVendor Advisory
- documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_2026-1_release_notes.htmnvdRelease Notes
- github.com/watchtowrlabs/watchTowr-vs-SolarWinds-WebHelpDesk-CVE-2025-40552-CVE-2025-40553/blob/main/watchTowr-vs-SolarWinds-WebHelpDesk-CVE-2025-40552-CVE-2025-40553.pynvd
News mentions
1- Buy A Help Desk, Bundle A Remote Access Solution? (SolarWinds Web Help Desk Pre-Auth RCE Chain(s))watchTowr Labs · Feb 25, 2026