CVE-2025-40536

HIGH KEV NUCLEI

SolarWinds Web Help Desk unauthenticated RCE

Title source: metasploit

Description

SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could allow an unauthenticated attacker to gain access to certain restricted functionality.

Exploits (1)

metasploit WORKING POC GREAT
by Jimi Sebree, sfewer-r7 · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/solarwinds_webhelpdesk_rce.rb

Nuclei Templates (1)

SolarWinds Web Help Desk < 12.8.8 Hotfix 1 (HF1) - Security Control Bypass
HIGHVERIFIEDby inokii
Shodan: http.favicon.hash:"1895809524"

Scores

CVSS v3 8.1
EPSS 0.6891
EPSS Percentile 98.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2026-02-12
VulnCheck KEV 2026-02-12
ENISA EUVD EUVD-2025-206418
CWE
CWE-693
Status published
Products (1)
solarwinds/web_help_desk < 2026.1
Published Jan 28, 2026
KEV Added Feb 12, 2026
Tracked Since Feb 18, 2026