Executive brief
SolarWinds Web Help Desk, a software platform used by IT teams to manage service requests and support tickets, is vulnerable to a denial-of-service attack. An attacker can exploit this flaw to exhaust the server's memory, causing the application to crash and become unavailable to users. This disruption can prevent IT staff from accessing support tickets and delay critical service delivery.
Technical details
SolarWinds Web Help Desk is vulnerable to a denial-of-service (DoS) attack classified under CWE-770 (Allocation of Resources Without Limits or Throttling). The vulnerability allows a remote, unauthenticated attacker to trigger excessive memory consumption on the Web Help Desk server. If successfully exploited, the server will crash due to insufficient memory, leading to a complete loss of availability for the service. The issue is addressed in version 2026.2 of the software.
Affected products
- SolarWinds Web Help Desk Versions prior to 2026.2
Timeline
- 2026-06-02: disclosed
- 2026-06-02: advisory