Executive brief
SolarWinds Web Help Desk, a software platform used for managing IT service requests and support tickets, is vulnerable to a critical security flaw that allows attackers to bypass login requirements. If the system is configured to use SAML 2.0 for single sign-on, an unauthorized user could gain full access to the help desk environment. This could lead to the exposure of sensitive support data, unauthorized modification of records, or complete disruption of help desk operations.
Technical details
A critical authentication bypass vulnerability (CWE-287) exists in SolarWinds Web Help Desk when configured with SAML 2.0 authentication. The flaw allows a remote, unauthenticated attacker to bypass the authentication process and gain unauthorized access to the application. The vulnerability is exploitable over the network with low complexity and requires no user interaction. SolarWinds has addressed this issue in Web Help Desk version 2026.2.1. Organizations using version 2026.1 or earlier with SAML enabled should upgrade immediately.
Affected products
- SolarWinds Web Help Desk 2026.1 and all previous versions
Timeline
- 2026-07-23: disclosed: First published by SolarWinds
- 2026-07-30: advisory: NVD advisory published