Skip to content
SolarWindsCVE-2026-28323

SolarWinds Web Help Desk: authentication bypass

Critical9.8CVE-2026-28323 · Published Jul 30, 2026 · updated Aug 17, 2026

SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2.0 authentication method to be enabled.

SolarWinds advisory

Affected versions

PackageAffectedFixed in
Web Help Desk
Product
<= 2026.1 and all previous versionsNo fix yet
Details and references

More SolarWinds advisories

All SolarWinds
Advisory
SolarWinds Serv-U: insecure direct object reference
Critical9.1Jul 21
SolarWinds Serv-U: improper access control
Critical9.1Jul 21
SolarWinds Serv-U: privilege escalation
Critical9.1Jul 21
SolarWinds Serv-U: insecure direct object reference
Critical9.1Jul 21
SolarWinds Serv-U: insecure direct object reference
Critical9.1Jul 21
SolarWinds Serv-U: cross-site scripting
Medium6.2Jul 21

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.