HomeIntelligenceBrief
VULNERABILITY BRIEF🟠 High Vulnerability

Critical Authentication Bypass Vulnerability (CVE‑2026‑28323) Discovered in SolarWinds Web Help Desk

SolarWinds Web Help Desk versions prior to 2026.2.1 contain a SAML‑based authentication bypass (CVE‑2026‑28323) that could let unauthenticated attackers gain access. The flaw highlights the need for robust SOC 2 access‑control and vulnerability‑management evidence.

LiveThreat™ Intelligence · 📅 August 03, 2026· 📰 cisecurity.org
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
4 recommended
📰
Source
cisecurity.org

Critical Authentication Bypass Vulnerability (CVE‑2026‑28323) Discovered in SolarWinds Web Help Desk

What Happened – Researchers identified multiple flaws in SolarWinds Web Help Desk, the most severe (CVE‑2026‑28323) allowing an unauthenticated, remote attacker to bypass authentication when SAML 2.0 is enabled. A secondary issue (CVE‑2026‑28299) can cause a denial‑of‑service crash. No public exploitation has been reported.

Why It Matters for Compliance & Audit Readiness

  • An authentication bypass directly challenges SOC 2 CC6 (Logical Access) and the requirement to enforce strong, documented access controls.
  • Continuous vulnerability management and timely patching are core evidence points for the SOC 2 CC7 (System Operations) safeguard.
  • Demonstrating a documented remediation workflow for SAML‑related configurations provides audit‑ready proof of due diligence.

Who Is Affected – Enterprises that deploy SolarWinds Web Help Desk across government, large‑ and medium‑size businesses, and SaaS‑focused IT service teams.

Recommended Actions

  • Apply SolarWinds Web Help Desk 2026.2.1 or later patches after testing.
  • Verify that SAML 2.0 is disabled if not required, or enforce MFA on SAML assertions.
  • Document the vulnerability in your vulnerability‑management process (Safeguard 7.1) and map remediation steps to SOC 2 controls.
  • Capture patch‑deployment logs and SAML‑configuration reviews as continuous audit evidence.

Source: CIS Advisory 2026‑077

Technical Notes

  • Attack Vector: Exploit of a public‑facing application (T1190) via SAML authentication bypass (CVE‑2026‑28323).
  • Impact: Potential unauthorized access to ticketing, asset, and knowledge‑base data.
  • Secondary Issue: Denial‑of‑service via memory exhaustion (CVE‑2026‑28299).

Source: CIS Advisory 2026‑077

📰 Original Source
https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-solarwinds-web-help-desk-could-allow-for-authentication-bypass_2026-077

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · SOC 2 Readiness

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your SOC 2 posture defensible.

See where you'd stand with Verisq AI Trust Operations →