← Intelligence Center

Multiple Vulnerabilities in SolarWinds Web Help Desk Could Allow for Authentication Bypass

PublishedAug 3, 2026
Updated
VendorSolarWinds
SeverityHigh
Known ExploitedNo
Advisory IDINTEL-000002
CVEs
CVE-2026-28299CVE-2026-28323
Products
  • SolarWinds Web Help Desk versions prior to 2026.2.1

Executive Summary

MS-ISAC Advisory 2026-077 (issued 7/30/2026): multiple vulnerabilities in SolarWinds Web Help Desk, the most severe of which could allow authentication bypass. A SAML authentication bypass vulnerability (CVE-2026-28323) affects deployments with the SAML 2.0 authentication method enabled, and a denial-of-service vulnerability (CVE-2026-28299) could cause the Web Help Desk server to crash due to insufficient memory. There are currently no reports of these vulnerabilities being exploited in the wild.

Municipal Impact

MS-ISAC rates the risk as High for large and medium government entities and Medium for small government entities; municipal help desk deployments should be updated.

SMB Impact

MS-ISAC rates the risk as High for large and medium business entities, Medium for small business entities, and Low for home users.

Recommended Actions

  1. Apply appropriate updates provided by SolarWinds to vulnerable systems immediately after appropriate testing.
  2. Review whether SAML 2.0 authentication is enabled, as the bypass only affects configurations where it is enabled.
  3. Follow CIS Safeguards for vulnerability management, automated vulnerability scanning, and remediation.

Grey Matter Analysis

Analysis pending review.

Need help with this advisory?

Contact Grey Matter to assess your exposure and prioritize remediation.

Contact Grey Matter