{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2025-26399/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2025-26399/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2025-26399/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2025-26399/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2025-26399/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2025-26399"},"sightings":{"href":"/api/v1/sightings/cve-2025-26399"}},"enrichments":{"cisa-kev":{"kev":true},"epss":{"epss":0.895,"kev":true,"percentile":0.99779},"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2025/CVE-2025-26399.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2025-26399\n\ninfo:\n  name: SolarWinds Web Help Desk < 12.8.7 - AjaxProxy Deserialization RCE\n  author: popy21\n  severity: critical\n  description: |\n    SolarWinds Web Help Desk contains an unauthenticated AjaxProxy deserialization remote code execution vulnerability, letting attackers run commands on the host machine without authentication, exploit requires no special privileges.\n  impact: |\n    Attackers can execute arbitrary commands on the host machine remotely without authentication, leading to full system compromise.\n  remediation: |\n    Update to the latest version that addresses this vulnerability.\n  reference:\n    - https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_12-8-7-hotfix-1_release_notes.htm\n    - https://www.solarwinds.com/trust-center/security-advisories/CVE-2025-26399\n    - https://nvd.nist.gov/vuln/detail/CVE-2025-26399\n    - https://labs.watchtowr.com/buy-a-help-desk-bundle-a-remote-access-solution-solarwinds-web-help-desk-pre-auth-rce-chain-s/\n    - https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-26399\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 9.8\n    cve-id: CVE-2025-26399\n    cwe-id: CWE-502\n    epss-score: 0.895\n    epss-percentile: 0.99779\n    cpe: cpe:2.3:a:solarwinds:web_help_desk:*:*:*:*:*:*:*:*\n  metadata:\n    verified: true\n    max-request: 1\n    vendor: solarwinds\n    product: web_help_desk\n    cisa-kev: true\n    shodan-query: http.favicon.hash:\"1895809524\"\n    fofa-query: icon_hash=\"1895809524\"\n  tags: cve,cve2025,solarwinds,webhelpdesk,deserialization,rce,kev,vkev,passive\n\nhttp:\n  - raw:\n      - |\n        GET /helpdesk/WebObjects/Helpdesk.woa HTTP/1.1\n        Host: {{Hostname}}\n\n    host-redirects: true\n    max-redirects: 2\n\n    matchers:\n      - type: dsl\n        dsl:\n          - 'status_code == 200'\n          - 'contains_any(body, \"Web Help Desk Software\", \"SolarWinds WorldWide\", \"HCS Web Help Desk\")'\n          - 'compare_versions(version, \"< 12.8.7\")'\n        condition: and\n\n    extractors:\n      - type: regex\n        name: build_token\n        part: body\n        group: 1\n        regex:\n          - \"\\\\?v=([0-9]+_[0-9]+_[0-9]+_[0-9]+)\"\n        internal: true\n\n      - type: dsl\n        name: version\n        dsl:\n          - 'replace(build_token, \"_\", \".\")'\n# digest: 4a0a004730450221008f21cf473c59ffebc633ddb2433f8c88b9be9a9103a8b972e407dd7a0548274302201a4cd2b38d6c2969056ee73c87e58dd8467462d3cd72c3e7a23e0558122be535:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2025-26399"}