SolarWinds Service Desk is affected by a broken access control vulnerability. The issue allows authenticated users to escalate privileges, leading to unauthorized data manipulation.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-6504 SolarWinds Service Desk is affected by a broken access control vulnerability. The issue allows authenticated users to escalate privileges, leading to unauthorized data manipulation.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 18 Mar 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 17 Mar 2025 20:15:00 +0000

Type Values Removed Values Added
Description SolarWinds Service Desk is affected by a broken access control vulnerability. The issue allows authenticated users to escalate privileges, leading to unauthorized data manipulation.
Title SolarWinds Service Desk Broken Access Control Vulnerability
Weaknesses CWE-653
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: SolarWinds

Published:

Updated: 2025-03-18T14:08:24.085Z

Reserved: 2025-02-08T00:19:09.395Z

Link: CVE-2025-26393

cve-icon Vulnrichment

Updated: 2025-03-18T14:08:21.224Z

cve-icon NVD

Status : Received

Published: 2025-03-17T20:15:14.140

Modified: 2025-03-17T20:15:14.140

Link: CVE-2025-26393

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.