Validated Containment Architectures are here. →Explore

Executive Summary

CVE-2026-28323 is a critical SAML authentication bypass vulnerability in SolarWinds Web Help Desk versions 2026.1 and earlier, discovered in July 2026. Attackers can forge SAML responses and bypass login screens entirely without valid credentials, gaining administrative access to help desk systems. The vulnerability stems from conditional signature verification that only validates SAML responses when certificates are present, and accepts unsigned responses even when certificates are configured. With a CVSS score of 9.8, this flaw allows complete takeover of help desk systems containing sensitive corporate data and service tickets through a single HTTP request.

This incident highlights the continued risks of legacy SAML implementations as organizations increasingly rely on federated identity for Zero Trust architectures, making proper SAML security validation more critical than ever.

Why This Matters Now

Legacy SAML implementations remain widespread in enterprise environments as organizations modernize identity systems, and this vulnerability demonstrates how authentication bypasses can completely undermine Zero Trust security models that depend on strong identity verification.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The vulnerability allows attackers to forge SAML responses without valid signatures or credentials because the application only performs signature verification when certificates are present and accepts unsigned responses even when certificates are configured.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Aviatrix Zero Trust CNSF would be highly relevant to this SolarWinds Web Help Desk incident by constraining lateral movement and reducing blast radius after the initial SAML authentication bypass. Zero Trust segmentation could limit attacker reach across internal systems and control data exfiltration paths.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Cloud Native Security Fabric may have limited the scope of initial compromise by providing enhanced visibility into authentication flows and controlling network access to the Web Help Desk application endpoints

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Zero Trust segmentation would likely have constrained the scope of administrative privileges by implementing identity-based access controls and limiting the blast radius of compromised administrative sessions across connected systems

Lateral Movement

Control: East-West Traffic Security

Mitigation: East-West traffic security controls would likely have constrained lateral movement by enforcing workload isolation and inspecting internal communications between the help desk system and connected LDAP/AD infrastructure

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Multicloud visibility and control capabilities may have detected anomalous session behavior and constrained the establishment of persistent command channels by monitoring application-level communications and administrative activities

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Egress security controls would likely have constrained data exfiltration by enforcing outbound traffic policies and monitoring database access patterns to limit unauthorized extraction of sensitive corporate information

Impact (Mitigations)

Despite the initial compromise, Zero Trust segmentation and egress controls would likely have reduced the overall business impact by constraining the scope of affected systems and limiting data exposure

Impact at a Glance

Affected Business Functions

  • IT Service Management
  • Help Desk Operations
  • Asset Tracking
  • SLA Workflow Management
Operational Disruption

Estimated downtime: 3 days

Financial Impact

Estimated loss: N/A

Data Exposure

Complete exposure of internal help desk systems including sensitive corporate data, service tickets, customer support records, and administrative credentials for organizations using affected SolarWinds Web Help Desk instances with SAML authentication enabled

Recommended Actions

  • Implement Zero Trust Segmentation with identity-based policies to prevent lateral movement from compromised help desk systems to critical enterprise resources
  • Deploy Cloud Firewall (ACF) with URL filtering and egress controls to block unauthorized outbound communications and data exfiltration attempts
  • Enable Multicloud Visibility & Control to detect anomalous authentication patterns and suspicious automation targeting SAML endpoints
  • Configure Egress Security & Policy Enforcement to prevent unauthorized data transfers from help desk systems to external destinations
  • Establish Threat Detection & Anomaly Response capabilities to identify authentication bypass attempts and baseline normal SAML authentication patterns

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image