Description
SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2.0 authentication method to be enabled.
Published: 2026-07-30
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

SolarWinds Web Help Desk is vulnerable to a SAML authentication bypass that operates when the SAML 2.0 authentication method is enabled. The flaw allows an attacker to bypass the normal credential validation process, enabling them to log in as an arbitrary user without valid credentials and potentially obtain administrative control of the system. This behavior is classified as CWE‑287, an authentication or authorization bypass weakness.

Affected Systems

The product affected is SolarWinds Web Help Desk. The vendor’s official fix is included in version 2026.2.1 and later; therefore any installation using a version prior to 2026.2.1 is potentially vulnerable, as the vulnerability is not mitigated until that release. This conclusion is inferred from the fact that the advisory recommends upgrading to the listed version and does not indicate that earlier releases are already safe.

Risk and Exploitability

The vulnerability has a CVSS score of 9.8, indicating critical severity, while the EPSS score of < 1% suggests a very low but nonzero probability of exploitation. The issue is not listed in the CISA KEV catalog. Attackers would need network access to the SAML endpoint and the ability to submit specially crafted SAML requests; the attack vector is inferred to be remote and requires the SAML 2.0 feature to be enabled.

Generated by OpenCVE AI on August 4, 2026 at 11:43 UTC.

Remediation

Vendor Solution

SolarWinds recommends customers upgrade to Web Help Desk version 2026.2.1 as soon as is practical.


OpenCVE Recommended Actions

  • Apply the vendor’s upgrade to Web Help Desk version 2026.2.1 or later.
  • Disable the SAML 2.0 authentication method until the patch is applied, if an upgrade cannot be performed immediately.
  • Monitor authentication logs for anomalous activity and enforce strong credential policies after the upgrade or disabling of SAML.

Generated by OpenCVE AI on August 4, 2026 at 11:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:solarwinds:web_help_desk:*:*:*:*:*:*:*:*

Thu, 30 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Solarwinds
Solarwinds web Help Desk
Vendors & Products Solarwinds
Solarwinds web Help Desk

Thu, 30 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Description SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2.0 authentication method to be enabled.
Title SolarWinds Web Help Desk SAML Authentication Bypass Vulnerability
Weaknesses CWE-287
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Solarwinds Web Help Desk
cve-icon MITRE

Status: PUBLISHED

Assigner: SolarWinds

Published:

Updated: 2026-07-31T03:56:15.917Z

Reserved: 2026-02-26T14:46:41.520Z

Link: CVE-2026-28323

cve-icon Vulnrichment

Updated: 2026-07-30T18:46:48.035Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-30T16:17:10.710

Modified: 2026-08-17T19:10:10.060

Link: CVE-2026-28323

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T11:45:03Z

Weaknesses