SolarWinds Web Help Desk SAML Auth Bypass
SolarWinds Web Help Desk has a SAML authentication bypass and DoS flaw, not yet exploited, patched in version 2026.2.1.
CISecurity/MS-ISAC issued an advisory covering multiple vulnerabilities in SolarWinds Web Help Desk, a widely used IT support and asset management platform. The most severe issue, CVE-2026-28323, allows an unauthenticated remote attacker to bypass authentication when SAML 2.0 authentication is enabled, potentially granting unauthorized access to the help desk system. A secondary vulnerability, CVE-2026-28299, can cause a denial-of-service condition by exhausting server memory, crashing the Web Help Desk service.
No exploitation in the wild has been reported at this time. Exploitation of the authentication bypass is conditional on SAML 2.0 being enabled, which limits the exposure to organizations using that specific configuration. SolarWinds has released version 2026.2.1 to address these issues, and CISecurity recommends prompt patching, vulnerability scanning, and standard hardening practices such as least privilege and network segmentation for affected deployments.
Mentioned in this report
Source reporting: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-solarwinds-web-help-desk-could-allow-for-authentication-bypass_2026-077
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free