← Back

CVE-2025-26399

nvd nist
Published: Sep 23, 2025Modified: Jun 17, 2026CISA KEV

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote code execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. This vulnerability is a patch bypass of CVE-2024-28988, which in turn is a patch bypass of CVE-2024-28986.

Affected (2)

1 product
Web Help Desk
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Solarwinds
Up to 12.8.6
Version 12.8.7

Timeline

No history available yet.