Critical Authentication Bypass Vulnerability (CVE‑2026‑28323) Discovered in SolarWinds Web Help Desk
What Happened – Researchers identified multiple flaws in SolarWinds Web Help Desk, the most severe (CVE‑2026‑28323) allowing an unauthenticated, remote attacker to bypass authentication when SAML 2.0 is enabled. A secondary issue (CVE‑2026‑28299) can cause a denial‑of‑service crash. No public exploitation has been reported.
Why It Matters for Compliance & Audit Readiness
- An authentication bypass directly challenges SOC 2 CC6 (Logical Access) and the requirement to enforce strong, documented access controls.
- Continuous vulnerability management and timely patching are core evidence points for the SOC 2 CC7 (System Operations) safeguard.
- Demonstrating a documented remediation workflow for SAML‑related configurations provides audit‑ready proof of due diligence.
Who Is Affected – Enterprises that deploy SolarWinds Web Help Desk across government, large‑ and medium‑size businesses, and SaaS‑focused IT service teams.
Recommended Actions
- Apply SolarWinds Web Help Desk 2026.2.1 or later patches after testing.
- Verify that SAML 2.0 is disabled if not required, or enforce MFA on SAML assertions.
- Document the vulnerability in your vulnerability‑management process (Safeguard 7.1) and map remediation steps to SOC 2 controls.
- Capture patch‑deployment logs and SAML‑configuration reviews as continuous audit evidence.
Source: CIS Advisory 2026‑077
Technical Notes
- Attack Vector: Exploit of a public‑facing application (T1190) via SAML authentication bypass (CVE‑2026‑28323).
- Impact: Potential unauthorized access to ticketing, asset, and knowledge‑base data.
- Secondary Issue: Denial‑of‑service via memory exhaustion (CVE‑2026‑28299).
Source: CIS Advisory 2026‑077