CVE-2026-28323 PUBLISHED

SolarWinds Web Help Desk SAML Authentication Bypass Vulnerability

Assigner: SolarWinds
Reserved: 26.02.2026 Published: 30.07.2026 Updated: 31.07.2026

SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2.0 authentication method to be enabled.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 9.8

Product Status

Vendor SolarWinds
Product Web Help Desk
Versions Default: unaffected
  • Version 2026.1 and all previous versions is affected

Solutions

SolarWinds recommends customers upgrade to Web Help Desk version 2026.2.1 as soon as is practical.

Credits

  • Dhabaleshwar Das finder

References

Problem Types

  • CWE-287 Improper Authentication CWE

Impacts

  • CAPEC-115 Authentication Bypass