Published on July 31, 2026

Attackers Can Exploit SolarWinds Web Help Desk Flaw to Trigger Memory-Based DoS


Severity

Critical

Detail

SolarWinds has released Web Help Desk (WHD) version 2026.2.1 to address multiple security vulnerabilities including a critical authentication bypass flaw and a high-severity denial-of-service (DoS) vulnerability that could impact the availability and security of affected systems.

The most critical issue, CVE-2026-28323, is a SAML authentication bypass vulnerability affecting deployments configured to use SAML 2.0 authentication. An attacker may exploit the flaw to gain unauthorized access to affected Web Help Desk instances under certain configurations.  SolarWinds also patched CVE-2026-28299, a high-severity improper resource allocation vulnerability that allows attackers to trigger excessive memory consumption by sending specially crafted requests to the application. Successful exploitation can exhaust server memory, causing the Web Help Desk service to become unstable or crash, resulting in a DoS condition.

In addition to these vulnerabilities, Web Help Desk 2026.2.1 introduces significant security enhancements including migration from the legacy Tomcat-based frontend to the Caddy web server, enforcement of TLS 1.2 and TLS 1.3, improved default security headers, reduced network exposure of internal services, and fixes for multiple third-party vulnerabilities affecting pgAdmin.

At the time of publication, there is no public evidence that either vulnerability has been actively exploited in the wild. However, organizations are strongly encouraged to upgrade immediately to reduce the risk of unauthorized access and service disruption.

CVE IDSummaryCVSS Score
CVE-2026-28323A SAML authentication bypass vulnerability in SolarWinds Web Help Desk that could allow unauthorized access to affected systems using SAML 2.0 authentication.9.8 (Critical)
CVE-2026-28299An improper resource allocation vulnerability that allows attackers to exhaust server memory through specially crafted requests, resulting in a denial-of-service condition.8.2 (High)

Affected Products

The vulnerabilities affect the following:

  • SolarWinds Web Help Desk versions prior to 2026.2.1
  • Deployments using SAML 2.0 authentication are specifically affected by CVE-2026-28323

Recommendation

Organizations should implement the following measures to reduce the risk of exploitation:

  • Upgrade SolarWinds Web Help Desk to version 2026.2.1 immediately.
  • Review and validate SAML authentication configurations to ensure secure deployment.
  • Monitor Web Help Desk servers for abnormal memory utilization or unexpected service interruptions that may indicate attempted denial-of-service attacks.
  • Verify that TLS 1.2 or TLS 1.3 is enabled and legacy protocols have been removed following the upgrade.

Source

https://cyberpress.org/solarwinds-web-help-desk/

https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_2026-2-1_release_notes.htm