CVE 5.3 MEDIUM

SolarWinds Web Help Desk XML External Entity Injection (XXE) Vulnerability_CVE-2025-26400

5.3 / 10
MEDIUM
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

Description

SolarWinds Web Help Desk was reported to be affected by an XML External Entity Injection (XXE) vulnerability that could lead to information disclosure. A valid, low-privilege access is required unless the attacker had access to the local server to modify configuration files.

Basic Information

ID CVE-2025-26400
Source SolarWinds
Published Jul 29, 2025 at 08:07
Modified Jul 29, 2025 at 13:47

Affected Product

Vendor SolarWinds
Product Web Help Desk
Version 12.8.6 and previous versions
Affected Versions SolarWinds Web Help Desk 12.8.6 and previous versions

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.