CVE-2026-28323

SolarWinds · Web Help Desk

SolarWinds Web Help Desk contains a SAML authentication bypass vulnerability that allows unauthenticated attackers to gain unauthorized access if SAML 2.0 is enabled.

Executive summary

A critical authentication bypass vulnerability in SolarWinds Web Help Desk enables unauthenticated attackers to gain unauthorized access to the application.

Vulnerability

The vulnerability is an improper authentication flaw (CWE-287) affecting the SAML 2.0 integration. It allows an unauthenticated remote attacker to bypass authentication mechanisms entirely, provided the SAML 2.0 authentication method is active.

Business impact

With a CVSS score of 9.8, this vulnerability represents a critical risk to the confidentiality, integrity, and availability of sensitive help desk data. Unauthorized access could allow attackers to view internal support tickets, sensitive user information, or administrative configurations, leading to significant data breaches and reputational damage.

Remediation

Immediate Action: Upgrade SolarWinds Web Help Desk to version 2026.2.1 immediately as recommended by the vendor.

Proactive Monitoring: Review authentication logs for irregular login patterns or unauthorized access attempts originating from external sources.

Compensating Controls: Disable SAML 2.0 authentication temporarily if the upgrade cannot be performed immediately, or restrict access to the Web Help Desk interface via network-level controls.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The severity of this authentication bypass necessitates immediate action. Administrators must prioritize upgrading to version 2026.2.1 to close this security gap, as the vulnerability is easily exploitable over the network and poses a direct threat to the security of the help desk environment.