Tools
Why SolarWinds Web Help Desk (WHD) is not affected by CVE-2026-34197
This article explains why SolarWinds Web Help Desk (WHD) is not affected by CVE-2026-34197, an Apache ActiveMQ.
First published date
Last published date
Overview
In 2026, the National Institute of Standards and Technology (NIST) published a security bulletin about CVE-2026-34197, a vulnerability affecting Apache ActiveMQ.
Product section
Cause
CVE-2026-34197 is an improper input validation vulnerability in Apache ActiveMQ that can result in code injection. For this vulnerability to be exploited, the following pre-requisites are required:
- web console exposed through a Jolokia endpoint
- valid, low privilege authentication
- default or permissive Jolokia access policy
- ability to supply a crafted URI
- outbound connectivity for the ActiveMQ broker
- Spring context auto-instantiation behavior
Resolution
While SolarWinds Web Help Desk (WHD) utilizes Apache ActiveMQ, it is in a non-default configuration which eliminates a lot of the pre-requisites needed to exploit CVE-2026-34197.