
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-40554 is a critical authentication bypass vulnerability in SolarWinds Web Help Desk that allows unauthenticated attackers to invoke specific privileged actions within the application. It affects SolarWinds Web Help Desk version 12.8.8 HF1 and all previous versions (all versions prior to 2026.1). The vulnerability was first published on January 28, 2026, and was discovered by Piotr Bazydlo working with watchTowr. It carries a CVSS v3.1 base score of 9.8 (Critical) (SolarWinds Advisory, WHD Release Notes).
The vulnerability is classified as an authentication bypass (CWE-1390: Weak Authentication), allowing network-based attackers to circumvent authentication controls and invoke protected actions within SolarWinds Web Help Desk without valid credentials. No user interaction or prior privileges are required, and the attack complexity is low, making it trivially exploitable over the network. The flaw was discovered by Piotr Bazydlo of watchTowr, who also identified related vulnerabilities (CVE-2025-40552 and CVE-2025-40553) in the same release cycle, and a detailed technical write-up including a pre-auth RCE chain was published by watchTowr Labs (SolarWinds Advisory, watchTowr Labs). A public proof-of-concept exploit is also available on GitHub (PoC GitHub).
Successful exploitation allows an unauthenticated remote attacker to invoke privileged actions within Web Help Desk, resulting in high impact to confidentiality, integrity, and availability. When chained with related deserialization RCE vulnerabilities (CVE-2025-40551, CVE-2025-40553) discovered in the same product, this authentication bypass can serve as the entry point for complete system compromise, enabling arbitrary command execution on the host machine. Approximately 170 SolarWinds Web Help Desk installations were identified as publicly exposed and vulnerable, increasing the risk of widespread exploitation and potential lateral movement within affected organizations (Rapid7 ETR, BleepingComputer).
A public proof-of-concept exploit is available on GitHub (published approximately March 2, 2026) (PoC GitHub). Active exploitation in the wild has been confirmed, and CISA added this vulnerability (along with related CVE-2025-40551) to its Known Exploited Vulnerabilities (KEV) catalog, mandating emergency patching for federal agencies (BleepingComputer CISA, The Hacker News CISA). The EPSS score is approximately 0.034% (0.000340), though real-world exploitation activity suggests the practical risk is significantly higher. Qualys scanner detection ID 530918 is available for this vulnerability. No specific threat actor attribution has been publicly confirmed at this time.
C:\Program Files\WebHelpDesk\ on Windows); new or modified configuration files.cmd.exe, powershell.exe, bash, curl, wget); unexpected network connections initiated by the WHD service account.SolarWinds has released a patch in Web Help Desk version 2026.1, which addresses CVE-2025-40554 along with five other critical vulnerabilities. Organizations should upgrade immediately from any version at or below 12.8.8 HF1 to WHD 2026.1 (SolarWinds Advisory, WHD Release Notes). As interim mitigations, implement network-level access controls to restrict access to Web Help Desk instances to trusted IP ranges only, monitor access logs for signs of unauthorized activity, and review recent logs for evidence of exploitation. Given CISA's KEV listing and confirmed active exploitation, this should be treated as a critical remediation priority with no delay (BleepingComputer CISA).
SolarWinds credited Piotr Bazydlo of watchTowr for responsible disclosure of CVE-2025-40554 and related vulnerabilities (SolarWinds Advisory). watchTowr Labs published a detailed technical blog post describing a pre-auth RCE chain combining the authentication bypass with deserialization flaws, drawing significant attention from the security community (watchTowr Labs). BleepingComputer, The Hacker News, Rapid7, Arctic Wolf, and CSO Online all covered the disclosure, with several noting the irony of critical vulnerabilities in IT management software given SolarWinds' history with the 2020 supply chain attack (BleepingComputer, Rapid7 ETR). The CIS also issued an advisory noting the potential for arbitrary code execution (CIS Advisory). Social media discussion was active across Mastodon, Bluesky, and Reddit security communities, with the vulnerability trending in CVEWatch roundups for multiple consecutive weeks.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."