Executive Summary
CVE-2026-28323 is a critical SAML authentication bypass vulnerability in SolarWinds Web Help Desk versions 2026.1 and earlier, discovered in July 2026. Attackers can forge SAML responses and bypass login screens entirely without valid credentials, gaining administrative access to help desk systems. The vulnerability stems from conditional signature verification that only validates SAML responses when certificates are present, and accepts unsigned responses even when certificates are configured. With a CVSS score of 9.8, this flaw allows complete takeover of help desk systems containing sensitive corporate data and service tickets through a single HTTP request.
This incident highlights the continued risks of legacy SAML implementations as organizations increasingly rely on federated identity for Zero Trust architectures, making proper SAML security validation more critical than ever.
Why This Matters Now
Legacy SAML implementations remain widespread in enterprise environments as organizations modernize identity systems, and this vulnerability demonstrates how authentication bypasses can completely undermine Zero Trust security models that depend on strong identity verification.
Attack Path Analysis
Attackers exploited CVE-2026-28323 SAML authentication bypass in SolarWinds Web Help Desk to gain unauthenticated administrative access by forging SAML responses. Once authenticated, they could escalate privileges through the help desk system's administrative functions, move laterally to access sensitive corporate data and service tickets, establish persistent command and control channels, exfiltrate sensitive corporate information and customer data, and ultimately disrupt IT service management operations.
Kill Chain Progression
Initial Compromise
Description
Attacker exploited CVE-2026-28323 SAML authentication bypass by crafting malicious SAML response with known admin username and posting to /helpdesk/WebObjects/Helpdesk.woa endpoint without valid signature verification
Related CVEs
CVE-2024-28323
CVSS 6.5A critical SAML authentication bypass vulnerability in SolarWinds Web Help Desk allows unauthenticated remote attackers to forge SAML responses and gain administrative access without valid credentials.
Affected Products:
SolarWinds Web Help Desk – <= 2024.1
Exploit Status:
proof of conceptCVE-2024-28299
CVSS 8.2A denial of service vulnerability in SolarWinds Web Help Desk that can be exploited in conjunction with the SAML authentication bypass.
Affected Products:
SolarWinds Web Help Desk – <= 2024.1
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
Valid Accounts
Modify Authentication Process: Hybrid Identity
Exploit Public-Facing Application
Domain Policy Modification: Trust Modification
Use Alternate Authentication Material: Application Access Token
Access Token Manipulation: Token Impersonation/Theft
Unsecured Credentials: Private Keys
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Strong User Authentication for Non-Console Access
Control ID: 8.2.1
NYDFS 23 NYCRR 500 – Multi-Factor Authentication
Control ID: 500.12
DORA – ICT Risk Management Framework
Control ID: Article 13
CISA ZTMM 2.0 – Identity Verification and Authentication
Control ID: Identity Pillar
NIS2 Directive – Cybersecurity Risk Management
Control ID: Article 21
ISO 27001:2022 – User Registration and De-registration
Control ID: A.9.2.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Information Technology/IT
Critical SAML authentication bypass in SolarWinds Web Help Desk exposes IT service management systems to unauthenticated administrative takeover and sensitive ticket data theft.
Government Administration
CVE-2026-28323 enables complete bypass of help desk authentication, compromising citizen service requests and internal administrative operations requiring HIPAA/NIST compliance controls.
Health Care / Life Sciences
Authentication bypass vulnerability threatens patient data confidentiality in help desk systems, violating HIPAA 164.312 requirements and exposing medical service tickets.
Financial Services
SAML authentication flaw allows unauthorized access to financial institution help desks, compromising customer support data and violating PCI DSS compliance frameworks.
Sources
- Signature Optional - Analysis of CVE-2026-28323https://bishopfox.com/blog/signature-optional-analysis-of-cve-2026-28323Verified
- SolarWinds Security Advisory - CVE-2024-28323https://www.solarwinds.com/trust-center/security-advisories/cve-2024-28323Verified
- Bishop Fox Analysis - Signature Optional Analysis of CVE-2024-28323https://bishopfox.com/blog/signature-optional-analysis-of-cve-2024-28323Verified
- NVD - CVE-2024-28323https://nvd.nist.gov/vuln/detail/CVE-2024-28323Verified
- SolarWinds Security Advisory - CVE-2024-28299https://www.solarwinds.com/trust-center/security-advisories/cve-2024-28299Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF would be highly relevant to this SolarWinds Web Help Desk incident by constraining lateral movement and reducing blast radius after the initial SAML authentication bypass. Zero Trust segmentation could limit attacker reach across internal systems and control data exfiltration paths.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Cloud Native Security Fabric may have limited the scope of initial compromise by providing enhanced visibility into authentication flows and controlling network access to the Web Help Desk application endpoints
Control: Zero Trust Segmentation
Mitigation: Zero Trust segmentation would likely have constrained the scope of administrative privileges by implementing identity-based access controls and limiting the blast radius of compromised administrative sessions across connected systems
Control: East-West Traffic Security
Mitigation: East-West traffic security controls would likely have constrained lateral movement by enforcing workload isolation and inspecting internal communications between the help desk system and connected LDAP/AD infrastructure
Control: Multicloud Visibility & Control
Mitigation: Multicloud visibility and control capabilities may have detected anomalous session behavior and constrained the establishment of persistent command channels by monitoring application-level communications and administrative activities
Control: Egress Security & Policy Enforcement
Mitigation: Egress security controls would likely have constrained data exfiltration by enforcing outbound traffic policies and monitoring database access patterns to limit unauthorized extraction of sensitive corporate information
Despite the initial compromise, Zero Trust segmentation and egress controls would likely have reduced the overall business impact by constraining the scope of affected systems and limiting data exposure
Impact at a Glance
Affected Business Functions
- IT Service Management
- Help Desk Operations
- Asset Tracking
- SLA Workflow Management
Estimated downtime: 3 days
Estimated loss: N/A
Complete exposure of internal help desk systems including sensitive corporate data, service tickets, customer support records, and administrative credentials for organizations using affected SolarWinds Web Help Desk instances with SAML authentication enabled
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation with identity-based policies to prevent lateral movement from compromised help desk systems to critical enterprise resources
- • Deploy Cloud Firewall (ACF) with URL filtering and egress controls to block unauthorized outbound communications and data exfiltration attempts
- • Enable Multicloud Visibility & Control to detect anomalous authentication patterns and suspicious automation targeting SAML endpoints
- • Configure Egress Security & Policy Enforcement to prevent unauthorized data transfers from help desk systems to external destinations
- • Establish Threat Detection & Anomaly Response capabilities to identify authentication bypass attempts and baseline normal SAML authentication patterns



