Home › Intelligence › Brief
VULNERABILITY BRIEF🟠 High Vulnerability

Critical Authentication Bypass Vulnerability (CVE‑2026‑28323) Discovered in SolarWinds Web Help Desk

SolarWinds Web Help Desk versions prior to 2026.2.1 contain a SAML‑based authentication bypass (CVE‑2026‑28323) that could let unauthenticated attackers gain access. The flaw highlights the need for robust SOC 2 access‑control and vulnerability‑management evidence.

LiveThreat™ Intelligence · 📅 August 03, 2026· 📰 cisecurity.org
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
4 recommended
📰
Source
cisecurity.org

Critical Authentication Bypass Vulnerability (CVE‑2026‑28323) Discovered in SolarWinds Web Help Desk

What Happened – Researchers identified multiple flaws in SolarWinds Web Help Desk, the most severe (CVE‑2026‑28323) allowing an unauthenticated, remote attacker to bypass authentication when SAML 2.0 is enabled. A secondary issue (CVE‑2026‑28299) can cause a denial‑of‑service crash. No public exploitation has been reported.

Why It Matters for Compliance & Audit Readiness

  • An authentication bypass directly challenges SOC 2 CC6 (Logical Access) and the requirement to enforce strong, documented access controls.
  • Continuous vulnerability management and timely patching are core evidence points for the SOC 2 CC7 (System Operations) safeguard.
  • Demonstrating a documented remediation workflow for SAML‑related configurations provides audit‑ready proof of due diligence.

Who Is Affected – Enterprises that deploy SolarWinds Web Help Desk across government, large‑ and medium‑size businesses, and SaaS‑focused IT service teams.

Recommended Actions

  • Apply SolarWinds Web Help Desk 2026.2.1 or later patches after testing.
  • Verify that SAML 2.0 is disabled if not required, or enforce MFA on SAML assertions.
  • Document the vulnerability in your vulnerability‑management process (Safeguard 7.1) and map remediation steps to SOC 2 controls.
  • Capture patch‑deployment logs and SAML‑configuration reviews as continuous audit evidence.

Source: CIS Advisory 2026‑077

Technical Notes

  • Attack Vector: Exploit of a public‑facing application (T1190) via SAML authentication bypass (CVE‑2026‑28323).
  • Impact: Potential unauthorized access to ticketing, asset, and knowledge‑base data.
  • Secondary Issue: Denial‑of‑service via memory exhaustion (CVE‑2026‑28299).

Source: CIS Advisory 2026‑077

📰 Original Source
https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-solarwinds-web-help-desk-could-allow-for-authentication-bypass_2026-077 ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your trust posture defensible.

See where you'd stand with Verisq AI Trust Operations →