Impact
SolarWinds Web Help Desk is vulnerable to a SAML authentication bypass that operates when the SAML 2.0 authentication method is enabled. The flaw allows an attacker to bypass the normal credential validation process, enabling them to log in as an arbitrary user without valid credentials and potentially obtain administrative control of the system. This behavior is classified as CWE‑287, an authentication or authorization bypass weakness.
Affected Systems
The product affected is SolarWinds Web Help Desk. The vendor’s official fix is included in version 2026.2.1 and later; therefore any installation using a version prior to 2026.2.1 is potentially vulnerable, as the vulnerability is not mitigated until that release. This conclusion is inferred from the fact that the advisory recommends upgrading to the listed version and does not indicate that earlier releases are already safe.
Risk and Exploitability
The vulnerability has a CVSS score of 9.8, indicating critical severity, while the EPSS score of < 1% suggests a very low but nonzero probability of exploitation. The issue is not listed in the CISA KEV catalog. Attackers would need network access to the SAML endpoint and the ability to submit specially crafted SAML requests; the attack vector is inferred to be remote and requires the SAML 2.0 feature to be enabled.
OpenCVE Enrichment