CVE-2026-28323: SolarWinds Web Help Desk SAML Authentication Bypass Vulnerability
SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2.0 authentication method to be enabled.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SolarWinds Web Help Deskto a version that resolves this vulnerability.Fixed in 2026.2.1 - Configuration
Ensure the SAML 2.0 authentication method is enabled, as required by SolarWinds for the SAML 2.0 authentication method.
SolarWinds Web Help Desk SAML 2.0 authentication method enabled = true
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28323?
The severity of CVE-2026-28323 is critical with a CVSS score of 9.8.
What vulnerability is associated with CVE-2026-28323?
CVE-2026-28323 is associated with a SAML authentication bypass vulnerability in SolarWinds Web Help Desk.
How can I fix CVE-2026-28323?
To fix CVE-2026-28323, users are advised to disable SAML 2.0 authentication until a patch is applied.
Which software is affected by CVE-2026-28323?
SolarWinds Web Help Desk is the software affected by CVE-2026-28323.
When was CVE-2026-28323 published?
CVE-2026-28323 was published on July 30, 2026.