📦

web_help_desk

Vendor: webhelpdesk

Actively Exploited 5 CISA KEV List
PoC / Exploits 5 Code Available
Total RCEs 5 Remote Access
Total CVEs 2 Total Indexed
Avg. EPSS 17.67% Exploit Prob.
Latest CVE CVE-2026-28299 Jun 02

Security Vulnerability Index

Page 1 / 1
8.2 CVSS

SolarWinds Web Help Desk is found to be affected by a denial-of-service vulnerability, which when exploited, could cause the Web Help Desk server to crash due to insufficient memory.

EPSS: 0.06%
9.8 CVSS
CVE-2025-40554
Exploit Found

SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that, if exploited, could allow an attacker to invoke specific actions within Web Help Desk.

EPSS: 6.29%
9.8 CVSS
CVE-2025-40553
RCE Exploit Found

SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication.

EPSS: 17.35%
9.8 CVSS
CVE-2025-40552
Exploit Found

SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that if exploited, would allow a malicious actor to execute actions and methods that should be protected by authentication.

EPSS: 8.55%
9.8 CVSS

SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication.

EPSS: 86.97%
7.5 CVSS

SolarWinds Web Help Desk was found to be susceptible to a hardcoded credentials vulnerability that, under certain situations, could allow access to administrative functions.

EPSS: 0.02%
8.1 CVSS

SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could allow an unauthenticated attacker to gain access to certain restricted functionality.

EPSS: 67.49%
9.8 CVSS
CVE-2025-26399
RCE Exploit Found

SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote code execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. This vulnerability is a patch bypass of CVE-2024-28988, which in turn is a patch bypass of CVE-2024-28986.

EPSS: 26.75%
9.8 CVSS

SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. This vulnerability was found by the ZDI team after researching a previous vulnerability and providing this report. The ZDI team was able to discover an unauthenticated attack during their research.  We recommend all Web Help Desk customers apply the patch, which is now available.  We thank Trend Micro Zero Day Initiative (ZDI) for its ongoing partnership in coordinating with SolarWinds on responsible disclosure of this and other potential vulnerabilities.

EPSS: 6.31%
5.3 CVSS

SolarWinds Web Help Desk was reported to be affected by an XML External Entity Injection (XXE) vulnerability that could lead to information disclosure. A valid, low-privilege access is required unless the attacker had access to the local server to modify configuration files.

EPSS: 0.03%