CVE-2026-28323
web_help_desk: Improper Authentication (CVE-2026-28323)
criticalEPSS 1.0%
Affected
- solarwinds/web_help_desk
lt *..2026.2.1
Description
SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2.0 authentication method to be enabled.
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
solarwindsweb_help_desk
2026.2.1fixed from 2026.2.1Metrics
Show all metrics
Severity
critical
103.95
no public PoC known
9.8
Published
2026-07-30 15:55 UTC
CWE-287
Weakness classes (CWE)
CWE-287Class
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
cwe.mitre.org →
References & sources
- https://www.solarwinds.com/trust-center/security-advisories/CVE-2026-28323vendor-advisory
- https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_2026-2-1_release_notes.htmrelease-notes
- https://documentation.solarwinds.com/en/success_center/whd/content/helpdesksecureconfiguration.htmx_secure-configuration-guide
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- Initial Analysis2026-08-17 19:10 UTC· nvd@nist.gov
- CPE Configuration: OR *cpe:2.3:a:solarwinds:web_help_desk:*:*:*:*:*:*:*:* versions up to (excluding) 2026.2.1
- Reference Type: SolarWinds: https://documentation.solarwinds.com/en/success_center/whd/content/helpdesksecureconfiguration.htm Types: Product
- Reference Type: SolarWinds: https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_2026-2-1_release_notes.htm Types: Release Notes, Vendor Advisory
- Reference Type: SolarWinds: https://www.solarwinds.com/trust-center/security-advisories/CVE-2026-28323 Types: Vendor Advisory
- CVE Modified2026-07-30 19:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-28323","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technical…