{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/vulnerability-management/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:solarwinds:web_help_desk:*:*:*:*:*:*:*:*","cpe:2.3:a:solarwinds:web_help_desk:12.8.3:-:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2024-28986"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Web Help Desk"],"_cs_severities":["high"],"_cs_tags":["web-application","security-bypass","vulnerability-management"],"_cs_type":"advisory","_cs_vendors":["SolarWinds"],"content_html":"\u003cp\u003eSolarWinds has disclosed a security vulnerability affecting Web Help Desk, which permits a remote, unauthenticated attacker to bypass established security controls. The flaw, tracked as CVE-2024-28986, impacts versions prior to 12.8.3. Successful exploitation of this vulnerability could allow unauthorized parties to access sensitive data or perform actions within the Web Help Desk application without legitimate credentials. This represents a significant risk for organizations that rely on the software for internal ticket management and IT service desk operations. Defenders should prioritize patching affected instances to version 12.8.3 or later to remediate the exposure.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability poses a substantial risk to organizations utilizing SolarWinds Web Help Desk for IT service management. If exploited, an unauthorized actor could gain access to the application, potentially leading to the exposure of internal incident reports, user credentials, or administrative configuration settings. Given the administrative nature of help desk software, successful exploitation could facilitate lateral movement into other internal systems by leveraging credentials or information harvested from the help desk platform.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate all SolarWinds Web Help Desk instances to version 12.8.3 or later immediately to resolve CVE-2024-28986.\u003c/li\u003e\n\u003cli\u003eReview web server access logs for anomalous requests directed at Web Help Desk, particularly those originating from untrusted or external IP addresses that attempt to access internal-only endpoints.\u003c/li\u003e\n\u003cli\u003eImplement restrictive access controls for the Web Help Desk administrative portal, ensuring it is not directly exposed to the public internet.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-31T09:28:23Z","date_published":"2026-07-31T09:28:23Z","id":"https://feed.craftedsignal.io/briefs/2026-07-solarwinds-whd-bypass/","summary":"A vulnerability in SolarWinds Web Help Desk, identified as CVE-2024-28986, allows remote unauthenticated attackers to bypass security measures, potentially leading to unauthorized access.","title":"SolarWinds Web Help Desk Security Bypass Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-07-solarwinds-whd-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Vulnerability-Management","version":"https://jsonfeed.org/version/1.1"}