Новости компьютерной безопасности:

  Latest News

Critical SolarWinds Flaw Lets Attackers Bypass Web Help Desk SAML Login

С сайта: Vulnerability(cybersecuritynews.com)

Critical SolarWinds Flaw Lets Attackers Bypass Web Help Desk SAML Login

Author: Abinaya

SolarWinds has patched a critical security vulnerability in its Web Help Desk platform that could allow attackers to bypass SAML-based authentication.

CVE-2026-28323 affects SolarWinds Web Help Desk deployments using SAML 2.0 single sign-on (SSO)and was fixed in version 2026.2.1, released on July 30, 2026.

SolarWinds assigned the vulnerability a critical CVSS severity score of 9.8. Security researcher Dhabaleshwar Das was credited with responsibly reporting the issue. CVE-2026-28323 is classified as a SAML authentication bypass vulnerability.

SAML, or Security Assertion Markup Language, is commonly used by organizations to connect applications with centralized identity providers such as Microsoft Entra ID, Okta, and Active Directory Federation Services (ADFS). It enables users to sign in once through a trusted identity provider and then access connected business applications.

SolarWinds Web Help Desk SAML Flaw
An authentication bypass in this process is particularly serious as it can defeat a crucial access-control boundary. If successfully exploited, an attacker could gain access to a vulnerable Web Help Desk instance without completing the expected SAML login process.

Depending on the account context and application permissions, unauthorized access could expose help desk tickets, user information, internal communications, IT asset data, and other operational information managed through the platform.

SolarWinds has not publicly disclosed technical details on how to exploit this vulnerability, the affected request paths, or any evidence of active exploitation.

However, organizations should treat this issue as urgent given its critical severity and the sensitive role that help desk platforms often play in enterprise environments.

Help desk portals are typically accessible to employees, contractors, and external users, making them attractive targets for attackers seeking initial access or sensitive internal data.

The SolarWinds vulnerability only affects deployments using SAML 2.0 authentication, but all administrators should apply the update as it includes multiple security fixes.

Web Help Desk version 2026.2.1 also addresses CVE-2026-28299, a high-severity denial-of-service flaw with a CVSS score of 8.2. This vulnerability could allow an attacker to crash a Web Help Desk server due to insufficient memory handling.

Additionally, the update incorporates fixes for multiple third-party pgAdmin vulnerabilities, including remote code execution, command injection, LDAP injection, and TLS certificate validation bypass issues. The latest release introduces a redesigned interface and a new Caddy-based front-end architecture.

SolarWinds now supports only TLS 1.2/1.3, enforces HTTPS, applies security headers, restricts internal services to local access, and removes server version details from responses.

Administrators should upgrade to Web Help Desk version 2026.2.1 as soon as possible, particularly if SAML SSO is enabled. Organizations upgrading from earlier versions than 2026.1 must first upgrade to 2026.1, verify normal operation, and then proceed to 2026.2.1.

Teams should test SAML authentication with their identity provider after the upgrade and review Web Help Desk access logs for unusual login activity or unexpected account sessions.

SolarWinds also noted that servlet authentication is no longer supported in Web Help Desk version 2026.2.1. Customers relying on that method should plan a migration to either SAML 2.0 or HTTP Header authentication, while ensuring that the newly deployed SSO configuration is fully tested and protected by the latest patch.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC  Now .



#Cyber_Security_News #Vulnerability #cyber_security #cyber_security_news

Оригинальная версия на сайте: Critical SolarWinds Flaw Lets Attackers Bypass Web Help Desk SAML Login
Вернуться к списку новостей К свежим новостям Здесь был google AdSense.
Вместо рекламы товаров началась политическая агитация.
Отключено до получения извинений.

Вернуться к списку новостей Здесь был google AdSense.
Вместо рекламы товаров началась политическая агитация.
Отключено до получения извинений.


Новости проекта CSN:

✉ CSN.net4me.net

Обновление сайта csn.net4me.net

Обновление сайта csn.net4me.net 💻
cyber security news
  • Физически мы переехали на новый сервер. Благодарим наших подписчиков и постоянных читателей за терпение и понимание.
  • Сайт csn.net4me.net полностью адаптирован для работы по шифрованному SSL соединению.
  • Изменен механизм обработки и отображения опасных и критических уязвимостей.

Благодарим что вы с нами.


#CSN_обновление_сайта
https://csn.net4me.net/cyber_security_8301.html

Дополнительный материал

О проекте CSN

Проект CSN.net4me.net родился 16 Марта 2018 года.
Проект находится в самом начале своего развития. Конечно оформление, наполнение будет меняться. Одно останется неизменным - самые свежие новости компьютерной и сетевой безопасности.

О проекте net4me

Проект net4me.net развивался как сборник готовых решений и документации по темам компьютерной безопасности, сетевых решений и СПО (в часности linux). Темпы развития IT отрасли оказались столь быстрыми, что некоторые знания, технологии и информация о них устаревали мгновенно. Тем не менее, некоторый материал net4me.net до сих пор востребован.

Об источниках

Новости берутся CSN из открытых и доступных каждому источников. Авторы проекта стараются подбирать авторитетные и проверенные источники. Но, тем не менее, не несут ответственности за содержимое новостей. В каждой новости указывается источник этой новости, её автор и ссылка на оригинал новости.

Информация

Если вы желаете чтобы новости вашего ресурса были размещены на сайте CSN, то свяжитесь с авторами проекта csn@net4me.net и предложите ссылку на rss или xml ленту новостей вашего ресурса. Любая предложенная информация будет рассмотрена редакцией.