Cyber News / Article / Multiple Vulnerabilities in SolarWinds Web Help Desk Could Allow for Authentication Bypass

Multiple Vulnerabilities in SolarWinds Web Help Desk Could Allow for Authentication Bypass
Multiple vulnerabilities have been discovered in SolarWinds Web Help Desk, the most severe of which could allow for authentication bypass. SolarWinds Web Help Desk software grants access to SolarWinds IT support, asset management, and knowledge base operations. A vulnerability in the Web Help Desk could allow an unauthenticated, remote attacker to bypass authentication and gain access. This does require the SAML 2.0 authentication method to be enabled.
There are currently no reports of these vulnerabilities being exploited in the wild.
Multiple vulnerabilities have been discovered in SolarWinds Web Help Desk the most severe of which could allow authentication bypass. Details of the vulnerabilities are as follows:
Tactic:Initial Access(TA0001):
Technique:Exploit Public-Facing Application(T1190):
Lower severity vulnerabilities include:
Successful exploitation of the most severe of these vulnerabilities could allow for authentication bypass. If the SAML 2.0 authentication method is not enabled, the vulnerability will not be able to be exploited.
We recommend the following actions be taken:
Copyright©2026 Center for Internet Security®
Related articles
JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies
4 days ago
Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication
5 days ago
Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws
7 days ago
You might Also like

Windows BitLocker Vulnerability Allows Attackers to Execute Malicious Code Remotely

Man gets 15 years for extorting women with AI-generated porn videos

