CVE-2025-26399 is a critical unauthenticated remote code execution vulnerability affecting SolarWinds Web Help Desk, stemming from an AjaxProxy deserialization flaw that bypasses previous patches. With a CVSS score of 9.8, it allows attackers to execute arbitrary commands on the host machine over the network with low complexity and no user interaction or privileges required. This vulnerability is actively exploited in the wild, listed on CISA's KEV catalog, and has confirmed exploit code available, leading to urgent patch deadlines for federal agencies.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 12.8.6CPE matchmatch criteria | cpe:2.3:a:solarwinds:web_help_desk:*:*:*:*:*:*:*:* | ||
12.8.7CPE matchmatch criteria | cpe:2.3:a:solarwinds:web_help_desk:12.8.7:-:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.