📦 Web Help Desk

by Solarwinds

🔍 What is Web Help Desk?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-40551

CRITICAL CVSS 9.8 Jan 28, 2026

SolarWinds Web Help Desk has an unauthenticated remote code execution vulnerability via untrusted data deserialization. Attackers can execute arbitrary commands on affected systems without authenticat...

CVE-2025-40552

CRITICAL CVSS 9.8 Jan 28, 2026

SolarWinds Web Help Desk contains an authentication bypass vulnerability that allows attackers to execute privileged actions without valid credentials. This affects all organizations running vulnerabl...

CVE-2025-40553

CRITICAL CVSS 9.8 Jan 28, 2026

SolarWinds Web Help Desk has an unauthenticated remote code execution vulnerability via untrusted data deserialization. Attackers can exploit this to execute arbitrary commands on affected systems wit...

CVE-2025-40554

CRITICAL CVSS 9.8 Jan 28, 2026

SolarWinds Web Help Desk contains an authentication bypass vulnerability that allows attackers to execute specific actions without proper credentials. This affects all organizations running vulnerable...

CVE-2025-26399

CRITICAL CVSS 9.8 Sep 23, 2025

CVE-2025-26399 is an unauthenticated remote code execution vulnerability in SolarWinds Web Help Desk's AjaxProxy component that allows attackers to execute arbitrary commands on affected systems. This...

CVE-2024-28988

CRITICAL CVSS 9.8 Sep 1, 2025

CVE-2024-28988 is a critical Java deserialization vulnerability in SolarWinds Web Help Desk that allows unauthenticated attackers to execute arbitrary code on affected systems. This affects all organi...

CVE-2024-28987

CRITICAL CVSS 9.1 Aug 21, 2024

CVE-2024-28987 is a hardcoded credential vulnerability in SolarWinds Web Help Desk that allows remote unauthenticated attackers to access internal functionality and modify data. This affects all organ...

CVE-2024-28986

CRITICAL CVSS 9.8 Aug 13, 2024

CVE-2024-28986 is a Java deserialization vulnerability in SolarWinds Web Help Desk that could allow remote code execution on the host system. While SolarWinds reports they couldn't reproduce unauthent...

CVE-2025-40537

HIGH CVSS 7.5 Jan 28, 2026

SolarWinds Web Help Desk contains hardcoded credentials that could allow attackers to access administrative functions under certain conditions. This affects all organizations running vulnerable versio...

CVE-2025-40536

HIGH CVSS 8.1 Jan 28, 2026

SolarWinds Web Help Desk contains a security control bypass vulnerability that allows unauthenticated attackers to access restricted functionality. This affects all organizations running vulnerable ve...

CVE-2024-28989

MEDIUM CVSS 5.5 Feb 11, 2025

SolarWinds Web Help Desk contains a hardcoded cryptographic key that could allow attackers to decrypt sensitive information stored or transmitted by the software. This affects all organizations runnin...