CVE-2025-40554

SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that, if exploited, could allow an attacker to invoke specific actions within Web Help Desk.
Configurations

Configuration 1 (hide)

cpe:2.3:a:solarwinds:web_help_desk:*:*:*:*:*:*:*:*

History

03 Feb 2026, 21:08

Type Values Removed Values Added
First Time Solarwinds
Solarwinds web Help Desk
CPE cpe:2.3:a:solarwinds:web_help_desk:*:*:*:*:*:*:*:*
References () https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_2026-1_release_notes.htm - () https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_2026-1_release_notes.htm - Release Notes
References () https://www.solarwinds.com/trust-center/security-advisories/CVE-2025-40554 - () https://www.solarwinds.com/trust-center/security-advisories/CVE-2025-40554 - Vendor Advisory

Information

Published : 2026-01-28 08:16

Updated : 2026-02-03 21:08


NVD link : CVE-2025-40554

Mitre link : CVE-2025-40554

CVE.ORG link : CVE-2025-40554


JSON object : View

Products Affected

solarwinds

  • web_help_desk
CWE
CWE-1390

Weak Authentication