CVE-2026-28323
SolarWinds Web Help Desk SAML Authentication Bypass Vulnerability
Description
SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2.0 authentication method to be enabled.
In plain language
AI Act nowWeb Help Desk installations below 2026.2.1 need urgent attention if they use SAML sign-in, because an outsider can gain full access without valid credentials.
Unauthenticated network authentication bypass in SolarWinds Web Help Desk’s handling of SAML 2.0 login requests, allowing full system access when SAML is enabled.
What to do now
- Check whether your Web Help Desk instance has SAML 2.0 authentication enabled and identify its installed version.
- Upgrade Web Help Desk to version 2026.2.1.
- If upgrading is delayed, disable SAML 2.0 authentication until the upgrade is complete.
- Review recent sign-in and administrator activity for unexpected access.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- ⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacksen·The Hacker News· Exploited Cisco Identity Services Engine zero-day
- SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCEen·The Hacker News· Patch SolarWinds Access Rights Manager rce
- Signature Optional - Analysis of CVE-2026-28323en-us·Bishop Fox· PoC SolarWinds Web Help Desk auth-bypass
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-28323 and every CVE in our database. Create a free account — no credit card required.
Create Free Account