Friday, September 11, 2026

Critical SolarWinds Web Help Desk Flaw Lets Attackers Bypass SAML Authentication

SolarWinds has released Web Help Desk (WHD) version 2026.2.1 to address a critical authentication bypass vulnerability.

This flaw could allow attackers to gain unauthorized access to affected systems by exploiting weaknesses in SAML-based single sign-on (SSO) implementations.

Tracked as CVE-2026-28323 and assigned a CVSS score of 9.8, the vulnerability impacts deployments where SAML 2.0 authentication is enabled. It could enable threat actors to bypass authentication controls and impersonate legitimate users without valid credentials.

SolarWinds Web Help Desk Flaw

Security researcher Dhabaleshwar Das responsibly disclosed the vulnerability, and its severity is particularly concerning given the potential impact on enterprise help desk environments that rely on centralised identity providers such as Okta, Azure AD, or ADFS.

According to SolarWinds, the flaw resides in the handling and validation of SAML authentication responses. Improper verification mechanisms could allow crafted assertions to be accepted as legitimate.

In a real-world scenario, an adversary with network access or the ability to intercept authentication flows could forge SAML responses, gaining privileged access to the WHD platform.

This would expose sensitive ticketing data, administrative controls, and potentially integrated backend systems. Help desk platforms often contain user credentials, internal communications, and infrastructure details, making successful exploitation potentially facilitate lateral movement, privilege escalation, and broader compromise within enterprise environments.

This issue is particularly alarming given WHD 2026.2.1’s increased reliance on modern SSO mechanisms, following the deprecation of legacy servlet authentication.

Organizations that have recently migrated to SAML-based authentication as part of upgrades may be at heightened risk if patches are not promptly applied.

SolarWinds confirmed that the vulnerability has been fully remediated in version 2026.2.1, which also includes multiple additional security enhancements, such as enforced HTTPS, stronger TLS configurations, and improved security headers via its new Caddy-based reverse proxy architecture.

In addition to the authentication bypass flaw, the release addresses several previously disclosed vulnerabilities, including a denial-of-service issue (CVE-2026-28299) that could allow attackers to crash WHD servers through memory exhaustion.

Fixes for vulnerabilities in third-party components, such as pgAdmin4, including command injection, remote code execution, and LDAP-related flaws, have also been incorporated, highlighting the cumulative security improvements in this release cycle.

Security experts recommend that organizations immediately upgrade to WHD 2026.2.1 and verify their SAML configurations, including identity provider settings and certificate validation processes.

Administrators should monitor authentication logs for anomalies, enforce strict access controls, and consider implementing additional verification measures, such as conditional access policies.

Given the critical nature of authentication-bypass vulnerabilities, unpatched systems could become high-value targets for threat actors seeking initial access to enterprise networks.

This release highlights the ongoing risks posed by SSO misconfigurations and implementation flaws, underscoring the need for rigorous validation of authentication workflows in enterprise software deployments.

ALERT: 20+ government sites delivered malware to businesses and citizens. See full attack research to check your own exposure.

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming...

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0...

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw

A recently disclosed vulnerability in ConfigServer Security & Firewall...

Hackers Weaponize AI Safety Guardrails to Hide Malware From LLM-Powered Security Scanners

Threat actors are adapting malware not only for conventional...

Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access

Threat actors are actively exploiting three vulnerabilities in JFrog...

Related Articles

Recent News