First published: Mon Mar 17 2025(Updated: )
SolarWinds Service Desk is affected by a broken access control vulnerability. The issue allows authenticated users to escalate privileges, leading to unauthorized data manipulation.
Credit: psirt@solarwinds.com
Affected Software | Affected Version | How to fix |
---|---|---|
SolarWinds Service Desk |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-26393 is classified as a critical vulnerability due to its potential for privilege escalation and unauthorized data manipulation.
To fix CVE-2025-26393, apply the latest security patches provided by SolarWinds for the Service Desk software.
Authenticated users of SolarWinds Service Desk are affected by CVE-2025-26393.
CVE-2025-26393 can facilitate unauthorized data manipulation through privilege escalation by authenticated users.
All versions of SolarWinds Service Desk are potentially vulnerable to CVE-2025-26393.