started · updated
SolarWinds Web Help Desk critical SAML bypass vulnerability (CVE‑2026‑28323) patched
SolarWinds disclosed a critical authentication bypass vulnerability (CVE‑2026‑28323) in its Web Help Desk product that affects deployments using SAML 2.0 single sign‑on. The flaw allows an attacker to bypass the SAML login process and potentially gain access to internal tickets, user data and other operational information. The vulnerability was assigned a CVSS severity of 9.8.
The issue was responsibly reported by security researcher Dhabaleshwar Das and has been fixed in version 2026.2.1, released on July 30 2026. The same update also addresses a high‑severity denial‑of‑service flaw (CVE‑2026‑28299) and several third‑party component vulnerabilities. Organizations running SolarWinds Web Help Desk with SAML authentication are advised to apply the patch immediately. No public evidence of active exploitation has been disclosed.
Entities
CVE‑2026‑28323 · Dhabaleshwar Das · SAML · SolarWinds · SolarWinds Web Help Desk