CVE-2025-40551 Details
Description
SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication.
A remote code execution vulnerability has been identified in SolarWinds Web Help Desk. This issue arises from an untrusted data deserialization vulnerability that could allow an attacker to execute commands on the host machine. The vulnerability can be exploited without authentication.
Users can upgrade to SolarWinds Web Help Desk version 2026.1 or later, where this vulnerability has been addressed. For instructions on upgrading, see the WHD Installation and Upgrade Guide.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 4, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-40551 | CISA-ADP | US Government Resource |
| https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_2026-1_release_notes.htm | [email protected] | Release Notes |
| https://www.solarwinds.com/trust-center/security-advisories/CVE-2025-40551 | [email protected] | Vendor Advisory |
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability | Feb 3, 2026 | Feb 6, 2026 | Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-502 | Deserialization of Untrusted Data | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| solarwinds web help desk | < 2026.1 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 3, 2026 | Initial Analysis | [email protected] |
| Feb 3, 2026 | CVE Modified | CISA-ADP |
| Jan 28, 2026 | New CVE Received | [email protected] |