CVE-2025-40536

HIGH KEV NUCLEI

SolarWinds Web Help Desk unauthenticated RCE

Title source: metasploit
STIX 2.1

Exploitation Summary

CVE-2025-40536 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added February 12, 2026. EIP tracks 2 public exploits from researchers including victoriaalicex, Jimi Sebree, sfewer-r7, including a Metasploit module exploits/multi/http/solarwinds_webhelpdesk_rce. A Nuclei detection template is also available.

AI-analyzed exploit summary This repository provides a detailed technical analysis of CVE-2025-40536, a security control bypass vulnerability in SolarWinds Web Help Desk. It includes vulnerability mechanics, attack chain details, threat actor attribution, MITRE ATT&CK mapping, and remediation guidance.

Description

SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could allow an unauthenticated attacker to gain access to certain restricted functionality.

Exploits (2)

github WRITEUP
by victoriaalicex · poc
https://github.com/victoriaalicex/CVE-2025-40536-Analysis

This repository provides a detailed technical analysis of CVE-2025-40536, a security control bypass vulnerability in SolarWinds Web Help Desk. It includes vulnerability mechanics, attack chain details, threat actor attribution, MITRE ATT&CK mapping, and remediation guidance.

Classification
Writeup 100%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: SolarWinds Web Help Desk version 12.8.8 HF1 and prior
No auth needed
Prerequisites: Internet-facing SolarWinds Web Help Desk instance
devstral-2 · analyzed Jun 02, 2026 Full analysis →
metasploit WORKING POC GREAT
by Jimi Sebree, sfewer-r7 · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/solarwinds_webhelpdesk_rce.rb

This Metasploit module exploits CVE-2025-40536 (access control bypass) and CVE-2025-40551 (unsafe deserialization) to achieve unauthenticated RCE in SolarWinds Web Help Desk. It leverages JNDI injection and SMB server setup for payload delivery.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: SolarWinds Web Help Desk 12.7.x and 12.8.x
No auth needed
Prerequisites: Network access to target · SMB/LDAP service for payload delivery
devstral-2 · analyzed Feb 24, 2026 Full analysis →

Nuclei Templates (1)

SolarWinds Web Help Desk < 12.8.8 Hotfix 1 (HF1) - Security Control Bypass
HIGHVERIFIEDby inokii
Shodan: http.favicon.hash:"1895809524"

Scores

CVSS v3 8.1
EPSS 0.7038
EPSS Percentile 98.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2026-02-12
VulnCheck KEV 2026-02-12
ENISA EUVD EUVD-2025-206418
CWE
CWE-693
Status published
Products (1)
solarwinds/web_help_desk < 2026.1
Published Jan 28, 2026
KEV Added Feb 12, 2026
Tracked Since Feb 18, 2026