{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-28323/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-28323"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Web Help Desk"],"_cs_severities":["critical"],"_cs_tags":["authentication-bypass","saml","vulnerability","cve-2026-28323"],"_cs_type":"advisory","_cs_vendors":["SolarWinds"],"content_html":"\u003cp\u003eSolarWinds has disclosed a critical authentication bypass vulnerability, tracked as CVE-2026-28323, affecting the Web Help Desk (WHD) application. The vulnerability resides in the SAML 2.0 authentication integration. If SAML 2.0 authentication is enabled within the application settings, an unauthenticated remote attacker can bypass the standard login flow to gain unauthorized access to the system. This vulnerability has been assigned a CVSS v3.1 score of 9.8, reflecting its critical impact. The flaw affects Web Help Desk version 2026.1 and all preceding versions. Defenders must verify the current version of their WHD instances and ensure that those utilizing SAML for authentication are patched or secured according to vendor guidance.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance to identify internet-facing SolarWinds Web Help Desk instances.\u003c/li\u003e\n\u003cli\u003eAttacker probes the application to confirm if SAML 2.0 authentication is enabled.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious or crafted SAML assertion or bypass request targeting the WHD authentication endpoint.\u003c/li\u003e\n\u003cli\u003eThe application improperly validates the SAML response or authentication state, granting the attacker an authenticated session.\u003c/li\u003e\n\u003cli\u003eAttacker gains unauthorized access to the Web Help Desk administrative or user interface.\u003c/li\u003e\n\u003cli\u003eAttacker leverages this access to perform internal actions, potentially including data exfiltration or system modification depending on the privileges of the hijacked session.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an unauthenticated attacker to gain unauthorized access to the SolarWinds Web Help Desk instance. This may lead to the exposure of sensitive help desk tickets, internal user information, and potential administrative control over the help desk infrastructure. The vulnerability affects all organizations utilizing WHD with SAML 2.0 enabled, creating a significant risk of data breach and unauthorized system manipulation.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade to SolarWinds Web Help Desk version 2026.2.1 or later to remediate CVE-2026-28323.\u003c/li\u003e\n\u003cli\u003eAudit web server and application access logs for unusual patterns of authentication attempts directed at the SAML callback or login endpoints.\u003c/li\u003e\n\u003cli\u003eMonitor for anomalous administrative activities occurring from unexpected user sessions or source IP addresses within the help desk application.\u003c/li\u003e\n\u003cli\u003eReview the SolarWinds security advisory for CVE-2026-28323 and follow recommended hardening steps for Web Help Desk configurations.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-30T17:29:38Z","date_published":"2026-07-30T17:29:38Z","id":"https://feed.craftedsignal.io/briefs/2026-07-solarwinds-whd-saml-bypass/","summary":"SolarWinds Web Help Desk versions 2026.1 and prior are vulnerable to a critical authentication bypass via the SAML 2.0 implementation, allowing unauthenticated remote access.","title":"SolarWinds Web Help Desk SAML Authentication Bypass","url":"https://feed.craftedsignal.io/briefs/2026-07-solarwinds-whd-saml-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-28323","version":"https://jsonfeed.org/version/1.1"}