Ce mail provient de l'extérieur, restons vigilants

=====================================================================


                            CERT-Renater

                Note d'Information No. 2026/VULN804
_____________________________________________________________________

DATE                : 03/08/2026

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running Web Help Desk versions prior to
                                      2026.2.1.
 
=====================================================================
https://www.solarwinds.com/trust-center/security-advisories/cve-2026-28323
https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_2026-2-1_release_notes.htm#link12
_____________________________________________________________________

SolarWinds Web Help Desk SAML Authentication Bypass Vulnerability
(CVE-2026-28323) 

Summary

SolarWinds Web Help Desk is found to be affected by a SAML
authentication bypass vulnerability. This requires the SAML 2.0
authentication method to be enabled.


Affected Products

SolarWinds Web Help Desk 2026.1 and all previous versions


Fixed Software Release
SolarWinds Web Help Desk 2026.2.1


Acknowledgments
Dhabaleshwar Das


Advisory Details

Severity
9.8 Critical

Advisory ID

CVE-2026-28323

First Published
07/23/2026

Fixed Version
SolarWinds Web Help Desk 2026.2.1

CVSS Score
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

_____________________________________________________________

WHD 2026.2.1 release notes


Fixed CVEs

At SolarWinds, we prioritize the swift resolution of CVEs to
ensure the security and integrity of our software. In this
release, we have successfully addressed the following CVEs.


SolarWinds CVEs

SolarWinds would like to thank our Security Researchers below
for reporting on the issue in a responsible manner and working
with our security, product, and engineering teams to fix the
vulnerability.

This release also includes the fixes from 2026.2, which resolve
the following issues:

    SolarWinds Web Help Desk Denial-of-Service Vulnerability
    pgAdmin4 Command Injection Vulnerability
    pgAdmin4 Remote Code Execution (RCE) Vulnerability
    pgAdmin4 LDAP Injection Vulnerability
    pgAdmin4 LDAP Authentication TLS Validation Bypass
Vulnerability


See the details in the SolarWinds and third-party CVEs tables
for more information.


CVE-ID 	Vulnerability Title   Description   Severity   Credit

CVE-2026-28299 	SolarWinds Web Help Desk Denial-of-Service
Vulnerability 	SolarWinds Web Help Desk is found to be
affected by a denial-of-service vulnerability, which when
exploited, could cause the Web Help Desk server to crash
due to insufficient memory. 	8.2 High 	Tenable

CVE-2026-28323 	SolarWinds SAML Authentication Bypass
Vulnerability 	SolarWinds Web Help Desk is found to be
affected by a SAML authentication bypass vulnerability.
This requires the SAML 2.0 authentication method to be
enabled. 	9.8 Critical 	Dhabaleshwar Das


Third-party CVEs

CVE-ID 	Vulnerability title 	Description 	Severity

CVE-2025-12762 	pgAdmin4 Remote Code Execution (RCE)
Vulnerability pgAdmin versions up to 9.9 are affected by
a Remote Code Execution (RCE) vulnerability that occurs
when running in server mode and performing restores from
PLAIN-format dump files. This issue allows attackers to
inject and execute arbitrary commands on the server hosting
pgAdmin, posing a critical risk to the integrity and
security of the database management system and underlying
data. 	9.8 Critical

CVE-2025-12763 	pgAdmin4 Command Injection Vulnerability
pgAdmin 4 versions up to 9.9 are affected by a command
injection vulnerability on Windows systems. This issue is
caused by the use of shell=True during backup and restore
operations, enabling attackers to execute arbitrary system
commands by providing specially crafted file path input.
8.8 High

CVE-2025-13780 	pgAdmin4 Remote Code Execution (RCE)
Vulnerability 	pgAdmin versions up to 9.10 are affected
by a Remote Code Execution (RCE) vulnerability that occurs
when running in server mode and performing restores from
PLAIN-format dump files. This issue allows attackers to
inject and execute arbitrary commands on the server
hosting pgAdmin, posing a critical risk to the integrity
and security of the database management system and
underlying data. 	8.8 High

CVE-2025-9636 	pgAdmin4 Cross-Origin Opener Policy (COOP)
Vulnerability 	pgAdmin <= 9.7 is affected by a Cross-Origin
Opener Policy (COOP) vulnerability. This vulnerability allows
an attacker to manipulate the OAuth flow, potentially leading
to unauthorised account access, account takeover, data
breaches, and privilege escalation. 	7.9 High

CVE-2025-12764 	pgAdmin4 LDAP Injection Vulnerability
pgAdmin <= 9.9 is affected by an LDAP injection vulnerability
in the LDAP authentication flow that allows an attacker to
inject special LDAP characters in the username, causing the
DC/LDAP server and the client to process an unusual amount
of data DOS. 	7.5 High

CVE-2025-12765 	pgAdmin4 LDAP Authentication TLS Validation
Bypass Vulnerability 	pgAdmin <= 9.9 is affected by a
vulnerability in the LDAP authentication mechanism allows
bypassing TLS certificate verification.


=========================================================

+ CERT-RENATER        |    tel : 01-53-94-20-44         +
+ 23/25 Rue Daviel    |    fax : 01-53-94-20-41         +
+ 75013 Paris         |   email:cert@support.renater.fr +
=========================================================




