CVE-2026-28323
CVSS 9.8 CRITICAL: solarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability.
Vulnerabilities · 46 days ago
If Web Help Desk trusts SAML, that trust can be turned against it. On affected instances, a flaw in SAML assertion handling lets an attacker get past authentication and reach admin-capable functions without the real account credentials, so federated SSO does not keep the console safe by itself.
NCSC says SolarWinds has issued updates for CVE-2026-28323, a critical authentication bypass rated CVSS 9.8, and it affects systems with SAML authentication enabled. The issue sits in the login path that is supposed to prove identity, but instead can accept a forged assertion and hand over access to sensitive administrative features.
CVSS 9.8 CRITICAL: solarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability.
1 source covering this story
Kwetsbaarheid verholpen in SolarWinds Web Help Desk
De kwetsbaarheid betreft een authenticatiebypass in de SAML 2.0 authenticatie van SolarWinds Web Help Desk.
Part of the PlainSec briefing for 2026-08-01