External risk intelligence

SolarWinds Web Help Desk SAML Authentication Bypass Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-28323

SolarWinds Web Help Desk is a centralized application frequently deployed to manage enterprise support requests, often exposed to the internet or accessible via internal portals for user access. The vulnerability affects SAML authentication, a protocol commonly used in web-facing applications to facilitate external or federated identity access.

Authentication Bypass

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in SolarWinds Web Help Desk that could allow unauthorized access. This issue affects the SAML authentication method if it is enabled, potentially exposing sensitive information and system functions. The primary concern at this time is to confirm if this specific technology is in use and, if so, to what extent it may be exposed.

  • Authentication bypass in help desk software.
  • Critical flaw impacts unauthorized access.
  • Confirm relevance and exposure scope.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by targeting the SAML authentication process in SolarWinds Web Help Desk when SAML is enabled. This could allow an unauthenticated user to bypass normal login procedures, potentially leading to unauthorized access and control of the system.

  • SAML authentication must be enabled.
  • Unauthenticated access to the SAML endpoint.
  • Complete system compromise is possible.

Live Threat

Current exploitation, exposure, and threat context

When SAML 2.0 authentication is enabled in SolarWinds Web Help Desk, an attacker could potentially bypass authentication. This could lead to unauthorized access to the system.

  • Unauthorized access to system data.
  • Bypassing SAML authentication controls.
  • Compromise of system integrity.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in SolarWinds Web Help Desk affects organizations using SAML authentication. The first step is to identify all instances of Web Help Desk, confirm their SAML configuration, assess their exposure and business criticality, and then assign ownership for remediation planning.

  • Application or platform teams own the issue.
  • Verify SAML authentication is enabled.
  • Plan remediation based on exposure and criticality.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is SolarWinds Web Help Desk?

SolarWinds Web Help Desk is a centralized software platform used by enterprises to manage, track, and resolve IT support tickets and service requests. It functions as a web-based portal where employees submit requests and IT staff manage workflows, making it a critical hub for internal service operations.

How does CVE-2026-28323 affect security?

This vulnerability is classified as CWE-287, which refers to Improper Authentication. In the context of CVE-2026-28323, the software fails to properly verify user identity during the SAML login process. This flaw allows an attacker to skip standard login requirements, potentially gaining full, unauthorized access to the application and its data.

When can an attacker trigger this vulnerability?

The vulnerability can only be triggered if the SAML 2.0 authentication method is actively enabled within the Web Help Desk configuration. If your instance is configured to use traditional local authentication or other login methods instead of SAML 2.0, this specific bypass vulnerability is not applicable.

Is my instance at risk according to Halo Surface Signal?

Halo Surface Signal identifies this as a high-priority concern because Web Help Desk is frequently deployed in ways that make it accessible to users over the internet or through internal portals. Since it manages sensitive support requests and uses SAML for identity federation, any instance reachable by external or internal network traffic faces a heightened risk of unauthorized access.

What should I do to address this issue?

Start by auditing your environment to locate every instance of SolarWinds Web Help Desk. Check the administrative settings to confirm whether SAML 2.0 authentication is currently enabled. If it is, assess the business criticality and network exposure of those specific systems, then coordinate with your technical team to plan and apply the necessary security updates provided by the vendor.

References