CVE-2025-26393
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Published Mar 17, 2025
CWE ID 653
Summary
CVE-2025-26393 is a vulnerability affecting SolarWinds Service Desk. This issue involves broken access control, enabling authenticated users to escalate privileges beyond their designated levels. Unauthorized data manipulation is a potential consequence of this vulnerability, posing a significant risk to affected organizations. SolarWinds Service Desk users should apply the recommended patch or update as soon as possible to mitigate this vulnerability and secure their systems.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Service Desk