CVE-2025-26399
SolarWinds Web Help Desk Deserialization of Untrusted Data Privilege Escalation Vulnerability
Description
SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote code execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. This vulnerability is a patch bypass of CVE-2024-28988, which in turn is a patch bypass of CVE-2024-28986.
In plain language
AI Act nowCVE-2025-26399 is a critical SolarWinds Web Help Desk flaw that lets an attacker take full control of your server with a crafted network request—no login needed—so this is an urgent worry for any business using this software.
Unauthenticated remote code execution in SolarWinds Web Help Desk via specially crafted requests to the AjaxProxy component (CWE-502 deserialization of untrusted data), allowing attackers to run commands on the server and fully compromise the host.
What to do now
- Check whether you use SolarWinds Web Help Desk and identify the exact installed version.
- If your system is reachable from the internet, assume it is at risk because exploitation requires no authentication and user interaction.
- Upgrade SolarWinds Web Help Desk to version 12.8.7 HF1 as soon as possible.
- If you cannot upgrade right away, stop exposing Web Help Desk to the internet (limit access to trusted networks/VPN only) until mitigations are applied per SolarWinds guidance.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
3 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2025-26399 and every CVE in our database. Create a free account — no credit card required.
Create Free Account