
[CIVN-2026-0295] Denial-of-Service Vulnerability in SolarWinds Web Help Desk
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Denial-of-Service Vulnerability in SolarWinds Web Help Desk
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: HIGH
Software Affected
SolarWinds Web Help Desk versions prior to 2026.2
Overview
A vulnerability has been reported in SolarWinds Web Help Desk which could allow a remote attacker to cause a denial-of-service (DoS) condition on the targeted system.
Target Audience:
Individuals and organizations using SolarWinds products.
Risk Assessment:
High risk of denial-of-service (DoS).
Impact Assessment:
Service disruption, application crashes and temporary unavailability.
Description
SolarWinds Web Help Desk (WHD) is used by organizations to streamline IT support operations and service management processes.
The vulnerability exists in SolarWinds Web Help Desk due to improper allocation of resources without limits or throttling. A remote attacker can exploit this vulnerability by sending specially crafted HTTP or HTTPS requests.
Successful exploitation of this vulnerability could allow a remote attacker to a denial-of-service (DoS) condition on the targeted system.
Solution
Apply appropriate updates as mentioned:
https://www.solarwinds.com/trust-center/security-advisories/cve-2026-28299
References
https://www.solarwinds.com/trust-center/security-advisories/cve-2026-28299
CVE Name
CVE-2026-28299
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmooJLAACgkQ3jCgcSdc
ys/cxw//ZlXXzaL8u1f/bCiyXOI7eo55wjv9R/ttDcLd79JfMRGYjrMUl17sRZZ/
W/KpkEb58Ly2KFv9JP9Sa4I3I5rlvikrEfwY29g2rnutqNf/Zx1+2wEqyyzQqf0E
ijGguUxZLl5VzpXV8UWetLpMomqLkF5WM/g+JKGe8BHQhObgx9tbfZc1JssPAttS
lS9mstq8xkTRhS8HR90xtSjQXhiDdqvudy6YAp4l1j9fnNkBmDFEXFuKldt4G/gn
d+bwfez7pxmqO08AYUx/dZuwvgMtrvRnicjgVR0qM/WTc09A3V63DwhU7OuaPwrp
jt9EVzdwhL2IUUNaOfuKbsSHUVnwGzVefPpFEuqEVcOTlu68K5Jaxd0jrTNmOtCL
JkimGxOxfSfv3yV2WmzJHGGbVobLFvvKP586/psLHHLsJV+0E+QEpAK29kKCT/Ui
SRU9zDOJWKYuf58CyN2uGRaIzNgZ9cPLy109senTH/DcRw5aPPXsi9KcyneownnR
OMp/IIIn5XXVmPpSFfqupN9ul44nrud27prO5D4ceAqjQfuoey64ajoPSNUal8iN
KOZCPERQUpcr6Zao4xsTs5UEu826sJeLGIzUeDBPt/ITaxTMYRHa9TSdezP+bXi9
pv6WSiU7uxfPpyasxoxYLpFD2CTkzAsZNaW8m1A3V5AccayGieY=
=MdAC
—–END PGP SIGNATURE—–


