Enterprise & Mobile

Authentication & Access Bypass

SAML 2.0 Authentication Bypass in SolarWinds Web Help Desk

Successful exploitation allows a remote unauthenticated attacker to bypass SAML authentication and impersonate an existing privileged user.

9.8
/ 10
Critical
CVSS v3.1
ADVISORY ID
PS106
PUBLISHED
2026-07-30
CVE IDs
CVE-2026-28323
VENDORS
SolarWinds
PUBLIC EXPLOIT
None indexed
CWE
CWE-287
PRODUCT
SolarWinds Web Help Desk
CVSS VECTOR
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

SolarWinds Web Help Desk contains a critical authentication bypass vulnerability in its SAML 2.0 authentication implementation. The issue occurs when SAML 2.0 authentication is enabled. The application fails to properly enforce validation of incoming SAML assertions, allowing an unauthenticated attacker to submit a forged SAML response containing the username of an existing user or administrator.

During analysis of the affected build, it was observed that an unsigned SAML assertion containing NameID=admin could be submitted directly to the Assertion Consumer Service (ACS) endpoint. Web Help Desk accepted the assertion and created an authenticated administrator session without requiring valid credentials or a legitimate Identity Provider-signed assertion.

The vulnerable logic is located within the SamlConsumer implementation. Signature verification is not correctly enforced before the supplied SAML identity is trusted. The vulnerability was also successfully reproduced with an Identity Provider verification certificate configured, confirming that the issue is not limited to an insecure SAML configuration.

Affected
SolarWinds Web Help Desk 2026.1 and all previous versions, when SAML 2.0 authentication is enabled. SolarWinds recommends upgrading to 2026.2.1.
Vulnerability details

Vulnerability details

CVE-2026-28323
CWE-287
Critical | 9.8

SolarWinds Web Help Desk contains a critical authentication bypass in its SAML 2.0 implementation. Signature verification is not enforced before the supplied SAML identity is trusted, so a forged assertion naming an existing administrator creates an authenticated session.

Auth:
None (remote)
Impact:
Sensitive data disclosure, arbitrary data or code modification, denial of service
Impact

What an attacker can do

Successful exploitation allows a remote unauthenticated attacker to bypass SAML authentication and impersonate an existing privileged user. As a result: Administrative Account Takeover: An attacker can authenticate as an existing administrator or technician without knowing the account password. Unauthorized Access: The attacker can gain access to sensitive help desk information, tickets, user information, assets, and administrative functionality. Privilege Abuse: Administrative access may allow modification of application configuration, users, permissions, and other security-sensitive settings. Confidentiality and Integrity Impact: Sensitive organizational information may be accessed or modified through the compromised administrator account. No User Interaction Required: Exploitation can be performed remotely without requiring interaction from a legitimate user.

DISCLOSURE

Disclosure timeline

2026-07-30 CVE published

2026-07-30 Fixed version released (Web Help Desk 2026.2.1)

Credits

Dhabaleshwar Das