Tools

Why SolarWinds Web Help Desk (WHD) is not affected by CVE-2026-34197

This article explains why SolarWinds Web Help Desk (WHD) is not affected by CVE-2026-34197, an Apache ActiveMQ.

First published date

5/29/2026 5:53 PM

Last published date

5/29/2026 5:53 PM

Overview

In 2026, the National Institute of Standards and Technology (NIST) published a security bulletin about CVE-2026-34197, a vulnerability affecting Apache ActiveMQ.

Product section

Web Help Desk

Cause

CVE-2026-34197 is an improper input validation vulnerability in Apache ActiveMQ that can result in code injection. For this vulnerability to be exploited, the following pre-requisites are required:

  • web console exposed through a Jolokia endpoint
  • valid, low privilege authentication
  • default or permissive Jolokia access policy
  • ability to supply a crafted URI
  • outbound connectivity for the ActiveMQ broker
  • Spring context auto-instantiation behavior

Resolution

While SolarWinds Web Help Desk (WHD) utilizes Apache ActiveMQ, it is in a non-default configuration which eliminates a lot of the pre-requisites needed to exploit CVE-2026-34197.