Summary
CVE-2026-28323 is a critical SAML authentication bypass vulnerability in SolarWinds Web Help Desk, affecting all versions up to and including 2026.1. Carrying a CVSS score of 9.8 (Critical), the flaw allows an unauthenticated, remote attacker to bypass authentication controls entirely — requiring no privileges and no user interaction — when the SAML 2.0 authentication method is enabled. SolarWinds has released a patched version and advises immediate upgrade.
Technical details
- Root cause: Improper authentication (CWE-287) in the handling of SAML 2.0 authentication flows within the Web Help Desk application.
- Trigger condition: The vulnerability is exploitable only when the SAML 2.0 authentication method is configured and enabled on the instance.
- Attack vector: Remotely exploitable over the network; no privileges required, no user interaction required (
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). - Impact: Successful exploitation enables an unauthenticated attacker to bypass authentication controls and gain unauthorized access to the system, with high impact to confidentiality, integrity, and availability.
Affected software
- SolarWinds Web Help Desk — all versions up to and including 2026.1 (when SAML 2.0 authentication is enabled)
Severity
CVSS v3.1 base score: 9.8 (Critical)
Vector string: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Upgrade to SolarWinds Web Help Desk 2026.2.1, which contains the security fix for this vulnerability.
- Upgrade path note: Installations running a version earlier than 2026.1 must first upgrade to 2026.1, verify functionality, and then proceed to upgrade to 2026.2.1.
- If immediate patching is not feasible: Disabling the SAML 2.0 authentication method removes the specific attack surface for this vulnerability. Additionally, restrict network access to Web Help Desk instances to trusted IP ranges where operationally possible.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

