CVE-2026-28323: SolarWinds Web Help Desk

Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.

SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2.0 authentication method to be enabled.

Affected products

  • SolarWinds Web Help Desk: before 2026.2.1 (fixed in 2026.2.1)

Published 2026-07-30. Last modified 2026-08-17.