SolarWinds Service Desk Broken Access Control Vulnerability 

(CVE-2025-26393)

Summary

SolarWinds Service Desk is affected by a vulnerability where unauthorized authenticated requesters can override ticket states, potentially redirecting ticket flows and changing process behavior.

Affected Products

SolarWinds Service Desk

Fixed Software Release

SolarWinds Service Desk

Acknowledgments

Seif Abdelwahid