

SolarWinds Web Help Desk versions prior to 2026.2.1, used for IT support, asset management, and knowledge base operations.
A SAML authentication bypass and a denial-of-service flaw could allow unauthenticated access or server crashes.
Disclosed 4th August 2026; fixed version 2026.2.1 available now, requiring prompt upgrade for affected deployments.
Web Help Desk instances with SAML 2.0 authentication enabled and exposed to network-based attackers.
Improper SAML assertion validation allows authentication bypass; insufficient memory handling causes denial-of-service crashes.
An unauthenticated remote attacker exploits SAML flaws to bypass login, or triggers memory exhaustion remotely.
Authentication bypass grants unauthorized access to IT support and asset data; denial-of-service disrupts help desk availability.
Compromise risks exposure of sensitive IT support data and disruption of help desk operations organization-wide.
Upgrade SolarWinds Web Help Desk to version 2026.2.1 immediately after testing across all affected deployments.
Review SAML authentication logs for anomalous logins; monitor server memory usage for signs of exploitation attempts.
SolarWinds Documentation
Trusted by clients worldwide






Led by human expertise and powered by the VisionX platform, we provide you with a 24/7 unbeatable Managed Detection & Response capability giving you transparent and consolidated security solutions.




