CVE-2025-40554 is a critical authentication bypass vulnerability affecting SolarWinds Web Help Desk. An unauthenticated attacker can exploit this flaw remotely with low complexity to invoke arbitrary actions, leading to complete compromise of confidentiality, integrity, and availability. While not yet in CISA's KEV catalog, the vulnerability has high community discussion, multiple media reports indicating active exploitation, and publicly available Nuclei templates for detection.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2026.1CPE matchmatch criteria | cpe:2.3:a:solarwinds:web_help_desk:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.