


Perceptive Security
SOC/SIEM Consultancy

SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2.0 authentication method to be enabled.
Published:
29 juli 2026 om 22:00:00
Alert date:
30 juli 2026 om 17:11:53
Source:
nvd.nist.gov
Enterprise Applications, Identity & Access, Zero-Day Vulnerabilities
SolarWinds Web Help Desk is affected by a SAML authentication bypass vulnerability tracked as CVE-2026-28323. The vulnerability is exploitable only when the SAML 2.0 authentication method is enabled on the affected system. An attacker could potentially bypass authentication controls by exploiting weaknesses in the SAML 2.0 implementation. SolarWinds has published a security advisory and release notes for a patched version (WHD 2026.2.1). Users are advised to apply the available patch and review the secure configuration guidance provided by SolarWinds. The vulnerability is currently awaiting full analysis by NVD. Given the nature of authentication bypass vulnerabilities in enterprise help desk software, the risk is considered high, especially for organizations relying on SAML-based SSO. Administrators should prioritize patching or disabling SAML 2.0 authentication as a temporary mitigation if the patch cannot be applied immediately.
Technical details
Mitigation steps:
Affected products:
SolarWinds Web Help Desk
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-28323
https://documentation.solarwinds.com/en/success_center/whd/content/helpdesksecureconfiguration.htm
https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_2026-2-1_release_notes.htm
https://www.solarwinds.com/trust-center/security-advisories/CVE-2026-28323
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
