Article

    Cyber News / Article / Multiple Vulnerabilities in SolarWinds Web Help Desk Could Allow for Authentication Bypass

    Multiple Vulnerabilities in SolarWinds Web Help Desk Could Allow for Authentication Bypass
    -2026-08-03

    Multiple Vulnerabilities in SolarWinds Web Help Desk Could Allow for Authentication Bypass

    Multiple vulnerabilities have been discovered in SolarWinds Web Help Desk, the most severe of which could allow for authentication bypass. SolarWinds Web Help Desk software grants access to SolarWinds IT support, asset management, and knowledge base operations. A vulnerability in the Web Help Desk could allow an unauthenticated, remote attacker to bypass authentication and gain access. This does require the SAML 2.0 authentication method to be enabled.

    There are currently no reports of these vulnerabilities being exploited in the wild.

    Multiple vulnerabilities have been discovered in SolarWinds Web Help Desk the most severe of which could allow authentication bypass. Details of the vulnerabilities are as follows:

    Tactic:Initial Access(TA0001):

    Technique:Exploit Public-Facing Application(T1190):

    Lower severity vulnerabilities include:

    Successful exploitation of the most severe of these vulnerabilities could allow for authentication bypass. If the SAML 2.0 authentication method is not enabled, the vulnerability will not be able to be exploited.

    We recommend the following actions be taken:

    Copyright©2026 Center for Internet Security®

    Original source