PT-2026-5073 · Solarwinds · Solarwinds Web Help Desk

Published

2026-01-28

·

Updated

2026-02-10

·

CVE-2025-40551

CVSS v2.0
10
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SolarWinds Web Help Desk versions prior to 2026.1 SolarWinds Web Help Desk versions 12.8.8 HF1 and earlier
Description SolarWinds Web Help Desk is susceptible to an untrusted data deserialization vulnerability that allows attackers to execute commands on the host machine without authentication. This vulnerability, designated CVE-2025-40551, is actively being exploited and has been added to CISA’s Known Exploited Vulnerabilities (KEV) catalog. The vulnerability resides in the AjaxProxy component. Over 170 installations are reportedly exposed online. The vulnerability allows for remote code execution (RCE).
Recommendations SolarWinds Web Help Desk versions prior to 2026.1: Update to version 2026.1 immediately. SolarWinds Web Help Desk versions 12.8.8 HF1 and earlier: Update to version 2026.1 immediately.

Fix

RCE

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

BDU:2026-00960
CVE-2025-40551

Affected Products

Solarwinds Web Help Desk