<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Cve-2026-28323 - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/cve-2026-28323/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 30 Jul 2026 17:29:38 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/cve-2026-28323/feed.xml" rel="self" type="application/rss+xml"/><item><title>SolarWinds Web Help Desk SAML Authentication Bypass</title><link>https://feed.craftedsignal.io/briefs/2026-07-solarwinds-whd-saml-bypass/</link><pubDate>Thu, 30 Jul 2026 17:29:38 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-07-solarwinds-whd-saml-bypass/</guid><description>SolarWinds Web Help Desk versions 2026.1 and prior are vulnerable to a critical authentication bypass via the SAML 2.0 implementation, allowing unauthenticated remote access.</description><content:encoded><![CDATA[<p>SolarWinds has disclosed a critical authentication bypass vulnerability, tracked as CVE-2026-28323, affecting the Web Help Desk (WHD) application. The vulnerability resides in the SAML 2.0 authentication integration. If SAML 2.0 authentication is enabled within the application settings, an unauthenticated remote attacker can bypass the standard login flow to gain unauthorized access to the system. This vulnerability has been assigned a CVSS v3.1 score of 9.8, reflecting its critical impact. The flaw affects Web Help Desk version 2026.1 and all preceding versions. Defenders must verify the current version of their WHD instances and ensure that those utilizing SAML for authentication are patched or secured according to vendor guidance.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker performs reconnaissance to identify internet-facing SolarWinds Web Help Desk instances.</li>
<li>Attacker probes the application to confirm if SAML 2.0 authentication is enabled.</li>
<li>Attacker crafts a malicious or crafted SAML assertion or bypass request targeting the WHD authentication endpoint.</li>
<li>The application improperly validates the SAML response or authentication state, granting the attacker an authenticated session.</li>
<li>Attacker gains unauthorized access to the Web Help Desk administrative or user interface.</li>
<li>Attacker leverages this access to perform internal actions, potentially including data exfiltration or system modification depending on the privileges of the hijacked session.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows an unauthenticated attacker to gain unauthorized access to the SolarWinds Web Help Desk instance. This may lead to the exposure of sensitive help desk tickets, internal user information, and potential administrative control over the help desk infrastructure. The vulnerability affects all organizations utilizing WHD with SAML 2.0 enabled, creating a significant risk of data breach and unauthorized system manipulation.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade to SolarWinds Web Help Desk version 2026.2.1 or later to remediate CVE-2026-28323.</li>
<li>Audit web server and application access logs for unusual patterns of authentication attempts directed at the SAML callback or login endpoints.</li>
<li>Monitor for anomalous administrative activities occurring from unexpected user sessions or source IP addresses within the help desk application.</li>
<li>Review the SolarWinds security advisory for CVE-2026-28323 and follow recommended hardening steps for Web Help Desk configurations.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>authentication-bypass</category><category>saml</category><category>vulnerability</category><category>cve-2026-28323</category></item></channel></rss>