Skip to content
Vulnerabilities

Critical SolarWinds Flaw Lets Attackers Bypass Web Help Desk SAML Login

SolarWinds has patched a critical security vulnerability in its Web Help Desk platform that could allow attackers to bypass SAML-based authentication. CVE-2026-28323 affects SolarWinds Web Help Desk deployments using SAML 2.0 single sign-on (SSO)and was fixed in version 2026.2.1, released on July 30...

· Jul 31, 2026 · 3 min read · 👁 1 views
Critical SolarWinds Flaw Lets Attackers Bypass Web Help Desk SAML Login

SolarWinds has patched a critical security vulnerability in its Web Help Desk platform that could allow attackers to bypass SAML-based authentication.

CVE-2026-28323 affects SolarWinds Web Help Desk deployments using SAML 2.0 single sign-on (SSO)and was fixed in version 2026.2.1, released on July 30, 2026.

SolarWinds assigned the vulnerability a critical CVSS severity score of 9.8. Security researcher Dhabaleshwar Das was credited with responsibly reporting the issue. CVE-2026-28323 is classified as a SAML authentication bypass vulnerability.

SAML, or Security Assertion Markup Language, is commonly used by organizations to connect applications with centralized identity providers such as Microsoft Entra ID, Okta, and Active Directory Federation Services (ADFS). It enables users to sign in once through a trusted identity provider and then access connected business applications.

SolarWinds Web Help Desk SAML Flaw

An authentication bypass in this process is particularly serious as it can defeat a crucial access-control boundary. If successfully exploited, an attacker could gain access to a vulnerable Web Help Desk instance without completing the expected SAML login process.

Depending on the account context and application permissions, unauthorized access could expose help desk tickets, user information, internal communications, IT asset data, and other operational information managed through the platform.

SolarWinds has not publicly disclosed technical details on how to exploit this vulnerability, the affected request paths, or any evidence of active exploitation.

However, organizations should treat this issue as urgent given its critical severity and the sensitive role that help desk platforms often play in enterprise environments.

Help desk portals are typically accessible to employees, contractors, and external users, making them attractive targets for attackers seeking initial access or sensitive internal data.

The SolarWinds vulnerability only affects deployments using SAML 2.0 authentication, but all administrators should apply the update as it includes multiple security fixes.

Web Help Desk version 2026.2.1 also addresses CVE-2026-28299, a high-severity denial-of-service flaw with a CVSS score of 8.2. This vulnerability could allow an attacker to crash a Web Help Desk server due to insufficient memory handling.

Additionally, the update incorporates fixes for multiple third-party pgAdmin vulnerabilities, including remote code execution, command injection, LDAP injection, and TLS certificate validation bypass issues. The latest release introduces a redesigned interface and a new Caddy-based front-end architecture.

SolarWinds now supports only TLS 1.2/1.3, enforces HTTPS, applies security headers, restricts internal services to local access, and removes server version details from responses.

Administrators should upgrade to Web Help Desk version 2026.2.1 as soon as possible, particularly if SAML SSO is enabled. Organizations upgrading from earlier versions than 2026.1 must first upgrade to 2026.1, verify normal operation, and then proceed to 2026.2.1.

Teams should test SAML authentication with their identity provider after the upgrade and review Web Help Desk access logs for unusual login activity or unexpected account sessions.

SolarWinds also noted that servlet authentication is no longer supported in Web Help Desk version 2026.2.1. Customers relying on that method should plan a migration to either SAML 2.0 or HTTP Header authentication, while ensuring that the newly deployed SSO configuration is fully tested and protected by the latest patch.

Source: CybersecurityNews.com

Follow ShomoySoft for more: Follow on Facebook

💬 Comments (0)

Login to join the discussion.

No comments yet. Be the first!

Recommended for you