PT-2026-66511 · Solarwinds · Web Help Desk

·

CVE-2026-28323

·

Published

2026-07-30

·

Updated

2026-09-10

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SolarWinds Web Help Desk (affected versions not specified)
Description An authentication bypass exists when the SAML 2.0 authentication method is enabled. The application treats SAML signature verification as optional and skips required validation steps, allowing an attacker to forge an arbitrary SAML assertion to achieve full session takeover without credentials. This is achieved via a single crafted POST request to the SAML assertion consumer service endpoint.
Recommendations Apply the available patch immediately. As a temporary workaround, disable SAML SSO and use local authentication. Review authentication logs for unexpected SSO-authenticated sessions, specifically for service or admin accounts.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-28323

Affected Products

Web Help Desk