SolarWinds Web Help Desk < 2026.1 Multiple Vulnerabilities

critical Nessus Plugin ID 297225

Synopsis

The remote host is missing one or more security updates.

Description

The version of Solarwinds Web Help Desk installed on the remote host is prior to 2026.1. It is, therefore, affected by multiple vulnerabilities.

- SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine.
This could be exploited without authentication. (CVE-2025-40551)

- SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that if exploited, would allow a malicious actor to execute actions and methods that should be protected by authentication. (CVE-2025-40552)

- SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine.
This could be exploited without authentication. (CVE-2025-40553)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Solarwinds Web Help Desk version 2026.1 or later.

See Also

http://www.nessus.org/u?c9c85dc4

Plugin Details

Severity: Critical

ID: 297225

File Name: solarwinds_web_help_desk_2026_1.nasl

Version: 1.1

Type: combined

Agent: windows

Family: Misc.

Published: 1/30/2026

Updated: 1/30/2026

Configuration: Enable thorough checks (optional)

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Critical

Score: 9.0

CVSS v2

Risk Factor: Critical

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2025-40551

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Vulnerability Information

CPE: cpe:/a:solarwinds:web_help_desk

Required KB Items: installed_sw/Solarwinds Web Help Desk

Patch Publication Date: 1/28/2026

Vulnerability Publication Date: 1/28/2026

Reference Information

CVE: CVE-2025-40536, CVE-2025-40537, CVE-2025-40551, CVE-2025-40552, CVE-2025-40553, CVE-2025-40554

IAVA: 2026-A-0094