#VU122152 Improper access control in Web Help Desk - CVE-2025-40536
Published: January 30, 2026 / Updated: February 13, 2026
Web Help Desk
SolarWinds
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions. A remote non-authenticated attacker can bypass implemented security restrictions and under certain circumstances gain unauthorized access to the application, leading to application compromise.