CVE-2025-26399

Source
https://cve.org/CVERecord?id=CVE-2025-26399
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-26399.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-26399
Published
2025-09-23T05:15:35.777Z
Modified
2026-03-15T22:52:07.006660Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote code execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. This vulnerability is a patch bypass of CVE-2024-28988, which in turn is a patch bypass of CVE-2024-28986.

References

Affected packages

Git /

Affected ranges

Database specific

unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "12.8.6"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "12.8.7-NA"
            }
        ]
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-26399.json"