---
schema: 1
kind: vulnerability
title: "CVE-2026-28323 — SolarWinds Web Help Desk: unauthenticated SAML 2.0 authentication bypass on a helpdesk portal (CVSS 9.8)"
headline: "SolarWinds patches a full authentication bypass in Web Help Desk that needs nothing but a reachable instance with SAML 2.0 enabled"
summary: >
  SolarWinds Web Help Desk 2026.1 and all earlier versions carry CVE-2026-28323, a SAML authentication bypass an
  unauthenticated attacker can use to gain unauthorized access to the ticketing application; the only stated
  precondition is that SAML 2.0 authentication is enabled. SolarWinds scores it CVSS 9.8 and fixes it in Web Help Desk
  2026.2.1. NCSC-CH carried the advisory on 2026-07-31 and records the exploitation status as unknown. Web Help Desk
  is commonly deployed as an internet-facing self-service portal by IT service providers and public-sector helpdesks,
  which is where the exposure sits. The fixed release itself only shipped on 2026-07-30, so the patch window opened
  days rather than weeks ago; the same release also fixes a separate denial-of-service flaw, CVE-2026-28299.
discovered_at: "2026-08-01T04:31:06Z"
event_date: "2026-07-23"
run_id: 2026-08-01T0409Z-intel
priority: notable
immediate_action: null
tags: [vulnerabilities, auth-bypass, pre-auth, identity, patch-available]
regions: [global]
sectors: [public-sector, technology]
entities: []
techniques: [T1190]
affected_products: ["SolarWinds Web Help Desk"]
cves:
  - id: CVE-2026-28323
    cvss: "9.8"
    epss: null
    type: auth-bypass
    vector: zero-click
    auth: pre-auth
    status: [patch-available]
    affected: "SolarWinds Web Help Desk 2026.1 and all previous versions, with SAML 2.0 authentication enabled"
    fixed: "SolarWinds Web Help Desk 2026.2.1"
  - id: CVE-2026-28299
    cvss: "8.2"
    epss: null
    type: dos
    vector: zero-click
    auth: pre-auth
    status: [patch-available]
    affected: "SolarWinds Web Help Desk 2026.1 and all previous versions"
    fixed: "SolarWinds Web Help Desk 2026.2.1"
sources:
  - url: "https://www.solarwinds.com/trust-center/security-advisories/cve-2026-28323"
    publisher: "SolarWinds"
    date: "2026-07-23"
    role: primary
  - url: "https://www.solarwinds.com/trust-center/security-advisories/cve-2026-28299"
    publisher: "SolarWinds"
    date: "2026-07-30"
    role: primary
  - url: "https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_2026-2-1_release_notes.htm"
    publisher: "SolarWinds (Web Help Desk 2026.2.1 release notes)"
    date: "2026-07-30"
    role: primary
  - url: "https://security-hub.ncsc.admin.ch/#/posts/12820"
    publisher: "NCSC Switzerland (GovCERT.ch) Cyber Security Hub"
    date: "2026-07-31"
    role: corroborating
  - url: "https://www.heise.de/news/SolarWinds-Web-Help-Desk-Update-bessert-umgehbare-Authentifizierung-aus-11388191.html"
    publisher: "heise online"
    date: "2026-07-31"
    role: corroborating
closed_sources: []
evidence:
  - quote: "SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2.0 authentication method to be enabled."
    publisher: "SolarWinds"
  - quote: "Successful exploitation allows unauthenticated attackers to bypass authentication and gain unauthorized access to the application."
    publisher: "NCSC Switzerland (GovCERT.ch) Cyber Security Hub"
verification: multi-source
sourcing_note: >
  The vendor advisory was first published 2026-07-23 but the fixed release only shipped a week later: SolarWinds' own
  2026.2.1 release notes give a release date of 2026-07-30, one day before the NCSC-CH advisory and the heise report
  that put this in front of the constituency. `event_date` records the advisory's publication date. The CVSS score,
  vector, affected range and fixed release for the bypass come from SolarWinds' own advisory record; that advisory
  does not describe the bypass mechanism, so this entry does not characterise it. CVE-2026-28299's score, vector, affected range and
  fixed release are taken from its own SolarWinds advisory, the record that owns the identifier; both CVE records here
  therefore carry vendor-published CVSS vectors, and the `pre-auth` and `zero-click` values on each come from that
  vector's PR:N and UI:N rather than from inference. That advisory is cited to 2026-07-30, its last-updated date rather than its
  06/02/2026 first-published date, because the fixed-release value this entry takes from it reflects the updated
  state of the page. The two vendor pages disagree on the denial-of-service flaw's remediation boundary — its advisory names 2026.2.1 as the fixed release, while the 2026.2.1 release notes list it
  among fixes carried in from 2026.2. The advisory's version is recorded, per the rule that the owning record wins,
  and the divergence is stated in the body rather than silently resolved.
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
classification:
  reliability: A
  credibility: 1
watchlist_hit: false
actions:
  - "Inventory SolarWinds Web Help Desk instances, and for any running 2026.1 or earlier with SAML 2.0 authentication enabled, upgrade to 2026.2.1 — or disable the SAML 2.0 login method and fall back to local authentication until the upgrade lands, since SAML being enabled is the vulnerability's only stated precondition."
migrated_from: null
---

SolarWinds' advisory for `CVE-2026-28323` states that Web Help Desk "is found to be affected by a SAML authentication bypass vulnerability" and that exploitation "requires the SAML 2.0 authentication method to be enabled", listing the affected range as "SolarWinds Web Help Desk 2026.1 and all previous versions" and the fixed release as 2026.2.1 ([SolarWinds, 2026-07-23](https://www.solarwinds.com/trust-center/security-advisories/cve-2026-28323)). The same advisory record carries the severity as 9.8 Critical on the vector `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H` and credits the finding to Dhabaleshwar Das ([SolarWinds, 2026-07-23](https://www.solarwinds.com/trust-center/security-advisories/cve-2026-28323)). The fix was not available when that advisory went out: SolarWinds' own release notes for Web Help Desk 2026.2.1 give a release date of 2026-07-30 ([SolarWinds, 2026-07-30](https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_2026-2-1_release_notes.htm)), a week after the advisory's first publication, so operators have had a patch to apply for a matter of days. A second vendor-tracked flaw is fixed in the same build. SolarWinds' dedicated advisory for `CVE-2026-28299` describes a denial-of-service issue that "could cause the Web Help Desk server to crash due to insufficient memory", rates it 8.2 High on `CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H` — so likewise no credentials and no user interaction — lists the affected range as "SolarWinds Web Help Desk 2026.1 and all previous versions", names 2026.2.1 as the fixed release, and credits Tenable ([SolarWinds, 2026-07-30](https://www.solarwinds.com/trust-center/security-advisories/cve-2026-28299)). The 2026.2.1 release notes describe that same flaw differently, listing it among fixes the release "also includes ... from 2026.2" ([SolarWinds, 2026-07-30](https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_2026-2-1_release_notes.htm)). The two vendor pages disagree about whether the remediation boundary is 2026.2 or 2026.2.1; this entry records the per-CVE advisory's version, since that is the record that owns the identifier, and an operator on 2026.2 should not treat the release-notes phrasing as clearance. Switzerland's NCSC picked the advisory up on 2026-07-31, summarising the impact as "unauthenticated attackers ... bypass authentication and gain unauthorized access to the application" and recording the current exploitation status as unknown ([NCSC-CH, 2026-07-31](https://security-hub.ncsc.admin.ch/#/posts/12820)); heise reported it the same day and advised administrators to bring instances up to date promptly given the severity ([heise online, 2026-07-31](https://www.heise.de/news/SolarWinds-Web-Help-Desk-Update-bessert-umgehbare-Authentifizierung-aus-11388191.html)).

The reason this belongs on a shortlist rather than in a quarterly queue is where the product sits and how recently the fix landed, not the score. Web Help Desk is a service-desk and ticketing application, frequently published to the internet so staff and external users can raise and track tickets themselves, and an authentication bypass that needs no credentials and no user interaction turns that portal into anonymous read access to whatever the ticket store holds — the same class of platform whose compromise has repeatedly supplied attackers with credentials, internal documents and support attachments. No party reports exploitation and no proof-of-concept is public. Because the advisory withholds the mechanism, defenders cannot yet write a request-shape detection for it; that argues for closing the precondition rather than waiting to detect the attempt.

Detection concepts, telemetry class first. On any Web Help Desk instance still on an affected release, the observable to watch is in the application's own authentication and session audit trail: a session established for a user — particularly an administrative or technician role — with no matching assertion recorded on the identity-provider side, and sign-ins that do not follow the expected service-provider-initiated redirect sequence through the IdP. Correlating the application's session-creation records against the IdP's issued-assertion log for the same window is the concrete check; a session with no corresponding assertion is the discriminator, and it does not depend on knowing how the bypass is constructed. In web-access logs, requests reaching authenticated application paths without a preceding authentication transaction are the same signal one layer down. Hardening: upgrade to 2026.2.1, and where the upgrade cannot be scheduled immediately, removing the stated precondition by turning off the SAML 2.0 login method is the available lever.
