CVE-2025-26393

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Mar 17, 2025
CWE ID 653

Summary

CVE-2025-26393 is a vulnerability affecting SolarWinds Service Desk. This issue involves broken access control, enabling authenticated users to escalate privileges beyond their designated levels. Unauthorized data manipulation is a potential consequence of this vulnerability, posing a significant risk to affected organizations. SolarWinds Service Desk users should apply the recommended patch or update as soon as possible to mitigate this vulnerability and secure their systems.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share