Executive brief
SolarWinds Web Help Desk, a software platform used for managing IT service requests and support tickets, contains a critical security flaw. An attacker can exploit this vulnerability to gain full control over the server hosting the application without needing any login credentials. This could lead to the theft of sensitive support data, disruption of IT operations, or a complete takeover of the host system.
Technical details
SolarWinds Web Help Desk is vulnerable to an unauthenticated remote code execution (RCE) flaw due to the deserialization of untrusted data within the AjaxProxy component (CWE-502). This vulnerability represents a patch bypass of previous fixes for CVE-2024-28988 and CVE-2024-28986. An attacker can exploit this by sending a specially crafted request to the affected endpoint over the network, requiring no prior authentication or user interaction. Successful exploitation allows the attacker to execute arbitrary commands on the host machine with the privileges of the application. SolarWinds has released Web Help Desk 12.8.7 Hotfix 1 to address this issue.
Affected products
- SolarWinds Web Help Desk Up to and including 12.8.6, 12.8.7 before Hotfix 1
Timeline
- 2025-09-23: disclosed: Initial CVE assignment and publication by SolarWinds
- 2026-02-06: advisory: Third-party advisory regarding active exploitation published by Microsoft
- 2026-03-09: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) catalog