CVE-2025-26393: SolarWinds Service Desk Broken Access Control Vulnerability
Published Mar 17, 2025
·Updated
SolarWinds Service Desk is affected by a broken access control vulnerability. The issue allows authenticated users to escalate privileges, leading to unauthorized data manipulation.
Affected Software
1 affected component
SolarWinds Service Desk
Event History
Mar 17, 2025
CVE Published
via MITRE·08:07 PM
Data Sourced
via MITRE·08:07 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-26393?
CVE-2025-26393 is classified as a critical vulnerability due to its potential for privilege escalation and unauthorized data manipulation.
2
How do I fix CVE-2025-26393?
To fix CVE-2025-26393, apply the latest security patches provided by SolarWinds for the Service Desk software.
3
Who is affected by CVE-2025-26393?
Authenticated users of SolarWinds Service Desk are affected by CVE-2025-26393.
4
What attacks can CVE-2025-26393 facilitate?
CVE-2025-26393 can facilitate unauthorized data manipulation through privilege escalation by authenticated users.
5
What version of SolarWinds Service Desk is vulnerable to CVE-2025-26393?
All versions of SolarWinds Service Desk are potentially vulnerable to CVE-2025-26393.