SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication.
References
Configurations
History
03 Feb 2026, 21:10
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Solarwinds
Solarwinds web Help Desk |
|
| References | () https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_2026-1_release_notes.htm - Release Notes | |
| References | () https://www.solarwinds.com/trust-center/security-advisories/CVE-2025-40553 - Vendor Advisory | |
| CPE | cpe:2.3:a:solarwinds:web_help_desk:*:*:*:*:*:*:*:* |
Information
Published : 2026-01-28 08:16
Updated : 2026-02-03 21:10
NVD link : CVE-2025-40553
Mitre link : CVE-2025-40553
CVE.ORG link : CVE-2025-40553
JSON object : View
Products Affected
solarwinds
- web_help_desk
CWE
CWE-502
Deserialization of Untrusted Data
