VYPR
patchPublished Jul 31, 2026· 1 source

Critical SolarWinds Flaw Allows SAML Authentication Bypass in Web Help Desk

SolarWinds has released version 2026.2.1 to patch CVE-2026-28323, a critical vulnerability in its Web Help Desk platform that allows attackers to bypass SAML 2.0 single sign-on authentication.

SolarWinds has addressed a critical security vulnerability, identified as CVE-2026-28323, within its Web Help Desk platform. This flaw specifically impacts deployments utilizing SAML 2.0 single sign-on (SSO) and was resolved with the release of version 2026.2.1 on July 30, 2026. The vulnerability carries a critical CVSS score of 9.8, underscoring its severity. Security researcher Dhabaleshwar Das is credited with the responsible disclosure of this issue.

CVE-2026-28323 is categorized as a SAML authentication bypass vulnerability. SAML, or Security Assertion Markup Language, is a widely adopted standard for enabling centralized identity management, allowing users to authenticate once through a trusted provider like Microsoft Entra ID or Okta and access multiple connected applications. An authentication bypass within this framework is particularly concerning as it undermines a fundamental security control, potentially granting unauthorized access.

Successful exploitation of this vulnerability could allow an attacker to gain access to a vulnerable Web Help Desk instance without successfully completing the standard SAML login process. The potential impact of such unauthorized access is significant, as it could expose sensitive help desk tickets, user information, internal communications, IT asset data, and other critical operational details managed by the platform. The exact methods of exploitation and affected components have not been publicly detailed by SolarWinds, but the critical nature of the flaw warrants immediate attention.

While SolarWinds has not disclosed specific technical details regarding exploitation methods or evidence of active exploitation, the critical severity score and the central role of help desk platforms in enterprise environments suggest a high-risk scenario. These portals are often accessible to a broad range of users, including employees, contractors, and external parties, making them attractive targets for attackers seeking initial access or valuable internal data.

The update, version 2026.2.1, not only fixes the SAML bypass flaw but also addresses CVE-2026-28299, a high-severity denial-of-service vulnerability (CVSS 8.2) that could lead to server crashes due to insufficient memory handling. Additionally, the release includes patches for multiple third-party pgAdmin vulnerabilities, which encompassed risks such as remote code execution, command injection, LDAP injection, and TLS certificate validation bypass.

SolarWinds has also implemented several security enhancements in this release, including a redesigned interface, a new Caddy-based front-end architecture, and stricter security protocols. The company now exclusively supports TLS 1.2/1.3, enforces HTTPS, applies security headers, restricts internal services to local access, and removes server version details from responses.

Administrators are strongly advised to upgrade to Web Help Desk version 2026.2.1 as soon as possible, especially if SAML SSO is enabled. For those upgrading from versions prior to 2026.1, a two-step process is required: first upgrade to 2026.1, confirm normal operation, and then proceed to 2026.2.1. Post-upgrade, thorough testing of SAML authentication with the identity provider and a review of Web Help Desk access logs for any suspicious activity are crucial steps.

It is important to note that servlet authentication is no longer supported in version 2026.2.1. Organizations relying on this method must plan a migration to either SAML 2.0 or HTTP Header authentication, ensuring that the new SSO configuration is fully tested and secured with the latest patch.

Synthesized by Vypr AI