SolarWinds has patched a critical authentication bypass flaw in Web Help Desk that could allow unauthenticated attackers to access vulnerable instances when SAML 2.0 single sign-on is enabled. Tracked as CVE-2026-28323, the issue affects Web Help Desk 2026.1 and earlier and is classified under CWE-287. SolarWinds rated the bug CVSS 9.8, with impact spanning confidentiality, integrity, and availability, raising the risk of exposure of help desk tickets, user data, internal communications, and IT asset records.
The fix was released in Web Help Desk 2026.2.1, and SolarWinds said it has not disclosed exploit details or observed active exploitation. The same release also addresses CVE-2026-28299, a high-severity denial-of-service vulnerability, along with multiple pgAdmin issues. Organizations using SAML-based SSO on Web Help Desk have been urged to upgrade immediately, verify authentication behavior after patching, and review logs for signs of unauthorized access.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
SolarWinds fixed the SAML authentication bypass vulnerability CVE-2026-28323 in Web Help Desk version 2026.2.1. The release on July 30, 2026 also addressed CVE-2026-28299 and multiple pgAdmin vulnerabilities.
A newly received CVE record identified CVE-2026-28323 as a SAML authentication bypass affecting SolarWinds Web Help Desk 2026.1 and earlier when SAML 2.0 authentication is enabled. The vulnerability was assigned CWE-287 and a CVSS v3.1 vector indicating high impact to confidentiality, integrity, and availability.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cyber.gc.ca
Open sourcecybersecuritynews.com
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.