CVE-2025-40536: SolarWinds Web Help Desk Security Control Bypass Vulnerability
SolarWinds Web Help Desk contains a security control bypass vulnerability that could allow an unauthenticated attacker to gain access to certain restricted functionality.
Other sources
SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could allow an unauthenticated attacker to gain access to certain restricted functionality.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SolarWinds Web Help Deskto a version that resolves this vulnerability.Fixed in 2026.1 - Remove
Remove
SolarWinds Web Help Deskfrom your environment.Discontinue use or uninstall the product if mitigations are unavailable.
- Compensating control
Apply mitigations per vendor instructions and follow applicable BOD 22-01 guidance for cloud services.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-40536?
CVE-2025-40536 is classified as a high severity vulnerability due to its potential for allowing unauthenticated access to restricted functionality.
How can I fix CVE-2025-40536?
To remediate CVE-2025-40536, it is recommended to update SolarWinds Web Help Desk to the latest version that addresses this vulnerability.
Who is affected by CVE-2025-40536?
CVE-2025-40536 affects users of SolarWinds Web Help Desk software who have not applied the necessary security patches.
What is the risk of exploiting CVE-2025-40536?
Exploiting CVE-2025-40536 could allow attackers to bypass security controls and access sensitive functions without authentication.
When was CVE-2025-40536 discovered?
CVE-2025-40536 was identified in 2025 and has been acknowledged in security advisories by SolarWinds.