PT-2026-5072 · Solarwinds · Solarwinds Web Help Desk
Published
2026-01-28
·
Updated
2026-02-18
·
CVE-2025-40537
CVSS v3.1
7.5
High
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SolarWinds Web Help Desk versions prior to 12.8.1
Description
SolarWinds Web Help Desk is susceptible to a hardcoded credentials issue that, in certain scenarios, could allow access to administrative functions. Attackers can identify exposed instances through scanning and fingerprinting, then attempt authentication using the hardcoded credential pathway. Successful exploitation could lead to unauthorized access to the Web Help Desk user interface and API, enabling enumeration of tickets, users, and configuration details. This could also provide a foothold for broader internal abuse, such as data theft, phishing via tickets, and abuse of trusted integrations. The root cause is the use of hard-coded credentials (CWE-798) embedded in the application, which bypass normal authentication controls.
Recommendations
Upgrade SolarWinds Web Help Desk to version 12.8.1 or a newer patched version provided by SolarWinds.
Restrict access to the Web Help Desk immediately, allowing only access from VPNs or jump hosts and blocking direct internet exposure at the firewall or reverse proxy.
Add temporary detections and controls for suspicious authentication attempts and admin session creation.
Review authentication logs for anomalous successful logins and unusual admin actions.
Hunt for indicators of compromise on the Web Help Desk host, such as webshells, new scheduled tasks, and suspicious outbound traffic.
If exposed, isolate the server, preserve forensic snapshots, rotate credentials, and review connected systems for lateral movement.
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Solarwinds Web Help Desk