CVE-2026-28323
🟠 Łataj w tym tygodniu
Obejście uwierzytelnienia w SolarWinds Web Help Desk umożliwia dostęp bez hasła.
CVSS
9.8
EPSS
0.6%
Exploit
none
Vendor
solarwinds
Opis źródłowy (NVD)
SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2.0 authentication method to be enabled.
auth-bypass
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 9.8 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.6% |
| Opublikowano (NVD) | 2026-07-30 16:17:10 UTC |
| Ostatnia modyfikacja (NVD) | 2026-08-17 19:10:10 UTC |
Referencje
- https://documentation.solarwinds.com/en/success_center/whd/content/helpdesksecureconfiguration.htm (psirt@solarwinds.com) [Product]
- https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_2026-2-1_release_notes.htm (psirt@solarwinds.com) [Release Notes, Vendor Advisory]
- https://www.solarwinds.com/trust-center/security-advisories/CVE-2026-28323 (psirt@solarwinds.com) [Vendor Advisory]