Full Report
SolarWinds security advisory (AV26-766)
Analysis Summary
# Vulnerability: SolarWinds Web Help Desk SAML Authentication Bypass
## CVE Details
- **CVE ID:** CVE-2026-28323
- **CVSS Score:** 9.8 (Critical)
- **CWE:** CWE-287 (Improper Authentication) / CWE-306 (Missing Authentication for Critical Function)
## Affected Systems
- **Products:** SolarWinds Web Help Desk (WHD)
- **Versions:** All versions prior to 2026.2.1
- **Configurations:** Systems utilizing SAML (Security Assertion Markup Language) for Single Sign-On (SSO) authentication.
## Vulnerability Description
A critical authentication bypass vulnerability exists in the SolarWinds Web Help Desk (WHD) SAML implementation. Due to improper validation of SAML assertions, a remote, unauthenticated attacker can craft a malicious SAML response to bypass the authentication process. This allows the attacker to gain unauthorized access to the application, potentially with administrative privileges, depending on the targeted user account.
## Exploitation
- **Status:** Not currently reported as exploited in the wild (Note: Based on the advisory date of July 2026).
- **Complexity:** Low
- **Attack Vector:** Network (Remote)
## Impact
- **Confidentiality:** High (Full access to help desk tickets, user data, and system configurations)
- **Integrity:** High (Ability to modify tickets, change system settings, or manipulate user accounts)
- **Availability:** High (Potential to lock out legitimate users or disrupt service operations)
## Remediation
### Patches
- **Upgrade to Web Help Desk (WHD) version 2026.2.1** or later. This version contains the necessary security fixes to properly validate SAML assertions.
### Workarounds
- If immediate patching is not possible, organizations should consider temporarily disabling SAML authentication and reverting to local authentication or LDAP/Active Directory authentication until the patch can be applied.
## Detection
- **Indicators of Compromise:** Monitor application logs for unusual SAML login patterns, specifically logins originating from unexpected IP addresses or logins that do not correspond to legitimate Identity Provider (IdP) traffic.
- **Detection methods:** Review WHD access logs for successful logins to administrative accounts that bypass standard SSO workflows.
## References
- SolarWinds Trust Center Advisory: hxxps[://]www[.]solarwinds[.]com/trust-center/security-advisories/cve-2026-28323
- WHD 2026.2.1 Release Notes: hxxps[://]documentation[.]solarwinds[.]com/en/success_center/whd/content/release_notes/whd_2026-2-1_release_notes[.]htm
- Government of Canada Advisory (AV26-766): hxxps[://]www[.]cyber[.]gc[.]ca/en/alerts-advisories/solarwinds-security-advisory-av26-766