Security Advisory

CVE-2025-26400

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-07-29 08:07:38
Last updated 2025-07-29 13:47:18
Assigner SolarWinds
CVSS score 5.3
State PUBLISHED

Description

SolarWinds Web Help Desk was reported to be affected by an XML External Entity Injection (XXE) vulnerability that could lead to information disclosure. A valid, low-privilege access is required unless the attacker had access to the local server to modify configuration files.