4 min read
By: RedLegg's Cyber Threat Intelligence Team
About:
CVE-2025-40552 is a critical authentication bypass vulnerability in SolarWinds Web Help Desk caused by improper enforcement of access controls on certain application methods. A remote attacker may be able to bypass normal authentication requirements and interact with protected functionality without valid credentials. Successful exploitation could expose sensitive ticketing data, user information, and potentially administrative capabilities within the help desk platform.
RedLegg will occasionally communicate vulnerabilities released outside the usual release schedule to provide additional value to our customers. These emergency bulletins describe vulnerabilities or threats we classify as the highest severity level and warrant out-of-band emergency patching or mitigation action.
VULNERABILITIES
Authentication Bypass in SolarWinds Web Help Desk
CVSS Score: 9.8 (Critical, CVSS v3.1)
Identifier: CVE-2025-40552
Exploit or Proof of Concept (PoC):
No public reports of exploitation at the time of reporting.
Update/ Patch: