← Back to browse · API

CVE-2024-28987

Severity
CRITICAL
CVSS
9.1
EPSS
0.93208
Risk score
57.62
CISA KEV
Yes
PoC
Yes
Published
2024-08-21
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2024-26049, GHSA-4JQ7-4QMF-M333
Products
SolarWinds:Web Help Desk, SolarWinds:Web Help Desk 12.8.3 Hotfix 1 and previous versions
Sources
cisa.gov CVE-2024-28987
github 024a734dbc1940319362e366|CVE-2024-28987
euvd EUVD-2024-26049

Description

The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access internal functionality and modify data.

References