Junglewise Threat Intelligence

CVE-2025-40536: SolarWinds Web Help Desk security control bypass

CVE-2025-40536 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2026-02-12

Executive brief

SolarWinds Web Help Desk, a platform used for managing IT service requests and support tickets, contains a critical security flaw. This vulnerability allows an unauthorized person to bypass security controls and access restricted administrative or internal functions without needing a password. This could lead to the exposure of sensitive support data or unauthorized changes to the system, and it is currently being exploited in the wild.

Technical details

SolarWinds Web Help Desk is susceptible to a security control bypass (CWE-693) that allows unauthenticated remote attackers to access restricted functionality. The vulnerability stems from a failure in the protection mechanisms designed to gate access to sensitive components. An attacker can exploit this over the network without any user interaction or prior privileges. Successful exploitation could lead to full compromise of the application's data and functionality. This vulnerability has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation. Users should upgrade to version 2026.1 or later to remediate the issue.

Affected products

  • SolarWinds Web Help Desk All versions prior to 2026.1

Timeline

  • 2026-01-28: disclosed: Initial CVE publication by SolarWinds
  • 2026-02-03: advisory: NIST NVD initial analysis published
  • 2026-02-12: kev added: CISA added to Known Exploited Vulnerabilities catalog
  • 2026-02-12: patched: SolarWinds released version 2026.1 to address the issue

Related threats