CVE-2025-26399
SolarWinds Web Help Desk Deserialization of Untrusted Data Privilege Escalation Vulnerability
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- February 08, 2025
- Published Date
- September 23, 2025
- Last Updated
- March 10, 2026
- Vendor
- SolarWinds
- Product
- Web Help Desk
- Description
- SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote code execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. This vulnerability is a patch bypass of CVE-2024-28988, which in turn is a patch bypass of CVE-2024-28986.
- Tags
- Exploitation
- active
- Automatable
- Yes
- Technical Impact
- total
- Exploited in the Wild
- Yes (2026-06-01 12:09:49 UTC) Source
cisa
CVSS Scores
CVSS v3.1
9.8 - CRITICAL
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC Information
Exploit Status
References
Known Exploited Vulnerability Information
| Source | Added Date |
|---|---|
| CVE | 2026-06-01 12:09:49 UTC |
Timeline
-
CVE ID Reserved
-
CVE Published to Public
-
Added to KEVIntel