TL;DR
SolarWinds has patched a critical authentication bypass in SolarWinds Web Help Desk. Tracked as CVE-2026-28323, the SAML flaw carries a CVSS score of 9.8. The 2026.2.1 release also fixes a denial-of-service bug, CVE-2026-28299. SolarWinds reports no exploitation in the wild for either issue.
- Product: SolarWinds Web Help Desk
- Vulnerabilities: 2 flaws (CVE-2026-28323, CVE-2026-28299)
- Highest severity: 9.8 (Critical · CVSSv3)
- Worst impact: SAML Authentication Bypass
- Status: No confirmed exploitation yet
- Action: See vendor advisories
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-28323 | 9.8 | CWE-287 | — | Not exploited |
| CVE-2026-28299 | 8.2 | CWE-770 | — | Not exploited |
Why it matters
Web Help Desk handles IT tickets and asset data for many organizations. That data makes it a prize for attackers. An authentication bypass then lets an intruder skip the login step. Moreover, this product has drawn attackers before. Earlier WHD flaws landed on CISA’s exploited-vulnerabilities list. So a 9.8-rated bypass deserves fast action.
How the attack works
CVE-2026-28323 sits in the SAML sign-in path. According to SolarWinds, the flaw “requires the SAML 2.0 authentication method to be enabled.” Where it is, an attacker can slip past identity checks and reach the application. The second bug works differently. SolarWinds says CVE-2026-28299 “could cause the Web Help Desk server to crash due to insufficient memory.”
Affected versions
The fixes ship in SolarWinds Web Help Desk 2026.2.1, released July 30, 2026. This build also rolls up the 2026.2 patches, including several third-party pgAdmin4 fixes.
Patch and mitigation
Admins should install the 2026.2.1 update now. If your instance uses SAML 2.0, treat this as urgent. You can review the official release notes for the full CVE list. As a further step, keep Web Help Desk off the public internet.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.