CVE-2025-26400: SolarWinds Web Help Desk
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
SolarWinds Web Help Desk was reported to be affected by an XML External Entity Injection (XXE) vulnerability that could lead to information disclosure. A valid, low-privilege access is required unless the attacker had access to the local server to modify configuration files.
Affected products
- SolarWinds Web Help Desk: before 12.8.7 (fixed in 12.8.7)
Published 2025-07-29. Last modified 2026-06-17.