---
id: CVE-2025-40551
title: >-
  SolarWinds Web Help Desk Deserialization of Untrusted Data Remote Code
  Execution Vulnerability
summary: >-
  SolarWinds Web Help Desk was found to be susceptible to an untrusted data
  deserialization vulnerability that could lead to remote code execution, which
  would allow an attacker to run commands on the host machine. This could be
  exploited …
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cvssSource: cna
cwe:
  - CWE-502
vendor: SolarWinds
product: Web Help Desk
affected:
  - web_help_desk 12.8.8 HF1 and below
ssvc:
  exploitation: active
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-02-04T04:55:44.585122Z'
exploited: true
exploitAvailable: true
published: '2026-01-28'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T17:55:29.348Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2025-40551'
references:
  - url: 'https://www.solarwinds.com/trust-center/security-advisories/CVE-2025-40551'
  - url: >-
      https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_2026-1_release_notes.htm
tags:
  - cve.org
  - in-the-wild
  - exploit-available
  - kev
epss: 0.84181
epssPercentile: 0.99692
kev: true
kevDateAdded: '2026-02-03'
kevDueDate: '2026-02-06'
kevRansomware: false
exploits:
  metasploit:
    - exploit/multi/http/solarwinds_webhelpdesk_rce
  nuclei:
    - CVE-2025-40551
  checkedAt: '2026-10-07T18:42:55.499Z'
ingestedAt: '2026-10-07T18:42:20.911Z'
---

## Overview

SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication.

## Affected

- `web_help_desk 12.8.8 HF1 and below`

## Remediation

SolarWinds recommends customers upgrade to Web Help Desk version 2026.1.
