CVE-2025-26400

SolarWinds Web Help Desk was reported to be affected by an XML External Entity Injection (XXE) vulnerability that could lead to information disclosure. A valid, low-privilege access is required unless the attacker had access to the local server to modify configuration files.
Configurations

Configuration 1 (hide)

cpe:2.3:a:solarwinds:web_help_desk:*:*:*:*:*:*:*:*

History

17 Nov 2025, 16:11

Type Values Removed Values Added
References () https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_12-8-7_release_notes.htm - () https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_12-8-7_release_notes.htm - Release Notes, Vendor Advisory
References () https://www.solarwinds.com/trust-center/security-advisories/CVE-2025-26400 - () https://www.solarwinds.com/trust-center/security-advisories/CVE-2025-26400 - Patch, Vendor Advisory
First Time Solarwinds
Solarwinds web Help Desk
CPE cpe:2.3:a:solarwinds:web_help_desk:*:*:*:*:*:*:*:*
Summary
  • (es) Se informó que SolarWinds Web Help Desk se vio afectado por una vulnerabilidad de inyección de entidades externas XML (XXE) que podría provocar la divulgación de información. Se requiere un acceso válido con privilegios bajos, a menos que el atacante tuviera acceso al servidor local para modificar los archivos de configuración.

29 Jul 2025, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-29 08:15

Updated : 2025-11-17 16:11


NVD link : CVE-2025-26400

Mitre link : CVE-2025-26400

CVE.ORG link : CVE-2025-26400


JSON object : View

Products Affected

solarwinds

  • web_help_desk
CWE
CWE-611

Improper Restriction of XML External Entity Reference