Enterprise & Mobile
Authentication & Access Bypass
SAML 2.0 Authentication Bypass in SolarWinds Web Help Desk
Successful exploitation allows a remote unauthenticated attacker to bypass SAML authentication and impersonate an existing privileged user.
.png)
Overview
SolarWinds Web Help Desk contains a critical authentication bypass vulnerability in its SAML 2.0 authentication implementation. The issue occurs when SAML 2.0 authentication is enabled. The application fails to properly enforce validation of incoming SAML assertions, allowing an unauthenticated attacker to submit a forged SAML response containing the username of an existing user or administrator.
During analysis of the affected build, it was observed that an unsigned SAML assertion containing NameID=admin could be submitted directly to the Assertion Consumer Service (ACS) endpoint. Web Help Desk accepted the assertion and created an authenticated administrator session without requiring valid credentials or a legitimate Identity Provider-signed assertion.
The vulnerable logic is located within the SamlConsumer implementation. Signature verification is not correctly enforced before the supplied SAML identity is trusted. The vulnerability was also successfully reproduced with an Identity Provider verification certificate configured, confirming that the issue is not limited to an insecure SAML configuration.
Vulnerability details
SolarWinds Web Help Desk contains a critical authentication bypass in its SAML 2.0 implementation. Signature verification is not enforced before the supplied SAML identity is trusted, so a forged assertion naming an existing administrator creates an authenticated session.
What an attacker can do
Successful exploitation allows a remote unauthenticated attacker to bypass SAML authentication and impersonate an existing privileged user. As a result: Administrative Account Takeover: An attacker can authenticate as an existing administrator or technician without knowing the account password. Unauthorized Access: The attacker can gain access to sensitive help desk information, tickets, user information, assets, and administrative functionality. Privilege Abuse: Administrative access may allow modification of application configuration, users, permissions, and other security-sensitive settings. Confidentiality and Integrity Impact: Sensitive organizational information may be accessed or modified through the compromised administrator account. No User Interaction Required: Exploitation can be performed remotely without requiring interaction from a legitimate user.
Disclosure timeline
2026-07-30 CVE published
2026-07-30 Fixed version released (Web Help Desk 2026.2.1)
References
Credits
Dhabaleshwar Das
















