logo

Multiple Vulnerabilities in SolarWinds Web Help Desk Could Allow for Authentication Bypass

ID: 7b0d5203-d6d5-521f-91b2-2fb74cbdad12

STIX ID: report--7b0d5203-d6d5-521f-91b2-2fb74cbdad12

Feed Name: CISecurity.org Advisories

Threat Score
65/100

Date Published: 2026-08-03

Date Updated: 2026-08-04

...
...

Multiple vulnerabilities were identified in SolarWinds Web Help Desk, including a critical SAML 2.0 authentication bypass (CVE-2026-28323) that can allow authentication bypass when SAML authentication is enabled, and a lower-severity denial-of-service (CVE-2026-28299) that can crash the server due to insufficient memory. The report maps the issue to Initial Access (TA0001) via exploiting a public-facing application (T1190) and notes that the critical bypass is only exploitable if SAML 2.0 is in use.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.