CVE-2025-40536
HIGH KEV NUCLEISolarWinds Web Help Desk unauthenticated RCE
Title source: metasploitDescription
SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could allow an unauthenticated attacker to gain access to certain restricted functionality.
Exploits (1)
metasploit
WORKING POC
GREAT
by Jimi Sebree, sfewer-r7 · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/solarwinds_webhelpdesk_rce.rb
Nuclei Templates (1)
SolarWinds Web Help Desk < 12.8.8 Hotfix 1 (HF1) - Security Control Bypass
HIGHVERIFIEDby inokii
Shodan:
http.favicon.hash:"1895809524"
References (4)
Scores
CVSS v3
8.1
EPSS
0.6891
EPSS Percentile
98.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CISA KEV
2026-02-12
VulnCheck KEV
2026-02-12
ENISA EUVD
EUVD-2025-206418
CWE
CWE-693
Status
published
Products (1)
solarwinds/web_help_desk
< 2026.1
Published
Jan 28, 2026
KEV Added
Feb 12, 2026
Tracked Since
Feb 18, 2026