Junglewise Threat Intelligence

CVE-2025-40551: SolarWinds Web Help Desk untrusted data deserialization

CVE-2025-40551 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2026-02-03

Executive brief

SolarWinds Web Help Desk, a popular IT service management and ticketing platform, contains a critical security flaw that allows unauthorized individuals to take full control of the server. By sending a specially crafted request, an attacker can execute arbitrary commands on the host machine without needing any login credentials. This could lead to the complete theft of sensitive support tickets, customer data, and a total disruption of IT operations. This vulnerability is currently being exploited in the wild.

Technical details

A deserialization of untrusted data vulnerability (CWE-502) exists in SolarWinds Web Help Desk. The flaw allows an unauthenticated attacker to send malicious serialized objects over the network, which the application then processes without sufficient validation. Successful exploitation results in remote code execution (RCE) with the privileges of the application service. This vulnerability has been added to CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation. Users should update to version 2026.1 or later to remediate the issue.

Affected products

  • SolarWinds Web Help Desk Versions prior to 2026.1

Timeline

  • 2026-01-28: disclosed: Initial CVE entry received from SolarWinds
  • 2026-02-03: advisory: NVD and SolarWinds published full advisory details
  • 2026-02-03: kev added: CISA added the vulnerability to the Known Exploited Vulnerabilities catalog
  • 2026-02-03: patched: Fix available in version 2026.1

Related threats