Threat Advisory

SolarWinds Web Help Desk SAML Authentication Vulnerability

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in SolarWinds Web Help Desk. These flaws include a critical SAML authentication bypass and a denial-of-service issue affecting versions prior to the 2026.2.1 release. The authentication bypass allows attackers to skip identity checks and gain unauthorized access to the application, posing a severe risk to sensitive IT ticket and asset data. The denial-of-service vulnerability can disrupt operations by crashing the server due to insufficient memory. Given the product's history of being targeted, these vulnerabilities present a significant threat to organizational integrity and data security.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in SolarWinds Web Help Desk. These flaws include a critical SAML authentication bypass and a denial-of-service issue affecting versions prior to the 2026.2.1 release. The authentication bypass allows attackers to skip identity checks and gain unauthorized access to the application, posing a severe risk to sensitive IT ticket and asset data. The denial-of-service vulnerability can disrupt operations by crashing the server due to insufficient memory. Given the product's history of being targeted, these vulnerabilities present a significant threat to organizational integrity and data security.[emaillocker id="1283"]

  • CVE-2026-28323 with a CVSS score of 9.8 – This SAML authentication bypass allows an attacker to slip past identity checks and reach the application without logging in, provided the SAML 2.0 authentication method is enabled.
  • CVE-2026-28299 – This denial-of-service vulnerability could cause the Web Help Desk server to crash due to insufficient memory, potentially leading to service disruption.

The presence of a critical authentication bypass in a widely used IT management tool creates an urgent security situation for organizations relying on SolarWinds Web Help Desk. Successful exploitation could lead to unauthorized access to proprietary IT assets and complete operational paralysis through server crashes. Immediate attention is required to prevent potential data breaches and significant service disruptions.

RECOMMENDATION:

  • We recommend you to update SolarWinds Web Help Desk to version 2026.2.1.

REFERENCES:

The following reports contain further technical details:
https://securityonline.info/solarwinds-web-help-desk-saml-bypass/

[/emaillocker]
crossmenu