CVE-2026-28323: SolarWinds Web Help Desk SAML Authentication Bypass — Threadlinqs Intelligence
As of 2026-07-31, CVE-2026-28323: SolarWinds Web Help Desk SAML Authentication Bypass is a critical-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 23 indicators of compromise.
Threat ID: TL-2026-1789 · Severity: CRITICAL · CVSS: 9.8 · Status: TRACKING · Category: VULNERABILITY
A critical SAML 2.0 authentication bypass (CVE-2026-28323, CVSS 9.8, CWE-287) lets an unauthenticated network attacker submit a crafted SAML assertion that Web Help Desk accepts as legitimate,
SolarWinds Web Help Desk (WHD) versions 2026.1 and earlier contain a SAML 2.0 authentication bypass tracked as CVE-2026-28323 (CVSS 3.1 base score 9.8, vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, CWE-287 Improper Authentication). The flaw lies in how WHD validates inbound SAML authentication responses: improper verification of the assertion/signature allows a crafted SAML assertion to be accepted as legitimate, letting a remote, unauthenticated attacker impersonate any user federated through an identity provider such as Okta, Microsoft Entra ID (Azure AD), or Active Directory Federation Services (ADFS) without needing valid credentials. Exploitation requires only that the target deployment have SAML 2.0 SSO enabled and be reachable over the network; no user interaction or prior privileges are required. Successful exploitation grants unauthorized access to help desk tickets, requester/user PII, internal communications, and IT asset inventory data managed inside WHD, and could be used as a foothold into the broader IT environment WHD is trusted to administer.
SolarWinds fixed CVE-2026-28323 in Web Help Desk 2026.2.1, released 2026-07-30, in the same build that also patched CVE-2026-28299 (an unauthenticated memory-exhaustion denial-of-service flaw, CVSS 8.2) and several bundled pgAdmin4 third-party CVEs (remote code execution, command injection, LDAP injection, TLS certificate validation bypass). Version 2026.2.1 also replaces the legacy Tomcat front end with a Caddy-based reverse proxy that enforces TLS 1.2/1.3-only, HTTPS-by-default, and automatic security headers, and restricts internal WHD services to localhost. The vulnerability was responsibly disclosed by security researcher Dhabaleshwar Das and credited by SolarWinds in the 2026.2.1 release notes.
As of this research (2026-07-31), no public proof-of-concept or exploit code for CVE-2026-28323 has been located (including a GitHub/PoC-repository search), SolarWinds' own advisory states no exploitation details or affected request paths have been publicly disclosed, and the CVE does not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitability is therefore assessed as THEORETICAL/vendor-confirmed rather than actively weaponized at disclosure time.
That assessment carries real urgency, however, because SolarWinds Web Help Desk has a documented recent history of being weaponized rapidly after disclosure. A distinct, earlier batch of WHD flaws (CVE-2025-40551, CVE-2025-40552, CVE-2025-40553, CVE-2025-40554, CVE-2025-40536, CVE-2025-40537 -- unauthenticated deserialization RCE and authentication bypass in the AjaxProxy/WebObjects components, disclosed 2026-01-28 in WHD 2026.1) was already under active exploitation before public disclosure. Huntress incident-response telemetry places the earliest confirmed post-exploitation persistence artifact -- a QEMU-based SSH-tunnel backdoor registered as a scheduled task named 'TPMProfiler' -- at 2026-01-16 21:24:40 UTC, twelve days before SolarWinds' coordinated disclosure, indicating attackers had working exploit chains in hand ahead of the vendor advisory. CISA added CVE-2025-40551 to its Known Exploited Vulnerabilities catalog on 2026-02-03, triggering a BOD 22-01 remediation deadline of 2026-02-06 for federal civilian agencies, and Microsoft, Elastic Security Labs, and SOC Prime published coordinated technical analyses on 2026-02-06. Huntress independently began investigating a compromised WHD instance on 2026-02-07 and published a detailed intrusion timeline on 2026-02-08, corroborating the same tradecraft: attackers pivoting from an unauthenticated WHD foothold into full domain compromise via living-off-the-land command execution, abuse of legitimate remote-access/forensic tooling (Velociraptor, Cloudflare Tunnel, Zoho ManageEngine, a downloaded Visual Studio Code binary used as a tunneling LOLBin, QEMU-based SSH tunneling), registry-based disabling of endpoint security controls roughly 84 seconds after initi
Weaknesses (CWE)
CWE-287, CWE-347
Target sectors: information-technology, managed-service-providers, cross-sector
Target regions: Global
Detections & IOCs
As of 2026-08-10, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 23 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-28323, T1190, T1133, T1606, T1550, T1078, T1213, T1059, T1053, T1574, T1685