SAML Authentication Bypass in SolarWinds Web Help Desk
CVE-2026-28323

9.8CRITICAL

Key Information:

Vendor

Solarwinds

Vendor
CVE Published:
30 July 2026

What is CVE-2026-28323?

The SolarWinds Web Help Desk software is impacted by a vulnerability that allows an attacker to bypass SAML 2.0 authentication. This issue arises when the SAML authentication method is enabled. An attacker may exploit this vulnerability to gain unauthorized access to the system, compromising the integrity and security of user data. To mitigate this risk, users are advised to review their SAML configurations and apply any available patches or updates.

Affected Version(s)

Web Help Desk 2026.1 and all previous versions

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dhabaleshwar Das
.