CVE-2025-26400
29.07.2025, 08:15
SolarWinds Web Help Desk was reported to be affected by an XML External Entity Injection (XXE) vulnerability that could lead to information disclosure. A valid, low-privilege access is required unless the attacker had access to the local server to modify configuration files.Enginsight
| Vendor | Product | Version |
|---|---|---|
| solarwinds | web_help_desk | 𝑥 < 12.8.7 |
𝑥
= Vulnerable software versions