SAML Login Bypass Opens Web Help Desk Admin Access
If Web Help Desk trusts SAML, that trust can be turned against it. On affected instances, a flaw in SAML assertion handling lets an attacker get past authentication and reach admin-capable functions without the real account credentials, so federated SSO does not keep the console safe by itself.
NCSC says SolarWinds has issued updates for CVE-2026-28323, a critical authentication bypass rated CVSS 9.8, and it affects systems with SAML authentication enabled. The issue sits in the login path that is supposed to prove identity, but instead can accept a forged assertion and hand over access to sensitive administrative features.