
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-28299 is a denial-of-service vulnerability in SolarWinds Web Help Desk that allows unauthenticated remote attackers to crash the server by triggering a memory exhaustion condition. It affects SolarWinds Web Help Desk version 2026.1 and all previous versions; the fixed release is version 2026.2. The vulnerability was published on June 2, 2026, with Tenable credited for responsible disclosure. It carries a CVSS v3.1 base score of 8.2 (High) (SolarWinds Advisory, GitHub Advisory).
The root cause is classified as CWE-770 (Allocation of Resources Without Limits or Throttling), meaning the application fails to impose restrictions on the size or number of resources it allocates in response to incoming requests. An unauthenticated attacker can exploit this over the network with low complexity and no user interaction by sending crafted requests that cause the server to allocate memory without bound, ultimately exhausting available memory and crashing the Web Help Desk service. No specific technical write-up or proof-of-concept code has been publicly released as of the time of this report (SolarWinds Advisory, GitHub Advisory).
Successful exploitation results in a complete loss of availability for the Web Help Desk server, causing it to crash due to memory exhaustion and disrupting IT support operations for all users relying on the service. There is a low integrity impact noted in the CVSS vector, though the primary consequence is a denial of service. Confidentiality is not impacted, and there is no evidence of lateral movement potential or data exposure risk associated with this vulnerability (SolarWinds Advisory, GitHub Advisory).
top, or performance counters), leading up to a service crash.WHD backend or equivalent managed service), particularly if recurring in a short timeframe.SolarWinds has released a fix in SolarWinds Web Help Desk 2026.2, and all users running version 2026.1 or earlier should upgrade immediately (SolarWinds Advisory, WHD 2026.2 Release Notes). As a temporary workaround prior to patching, administrators should implement network-level access controls (e.g., firewall rules, VPN requirements) to restrict which hosts can reach the Web Help Desk service, reducing the attack surface for unauthenticated network-based exploitation. Monitoring server memory utilization for signs of abnormal consumption can help detect exploitation attempts early.
Heise Online covered the vulnerability with an article titled "Attackers can disable SolarWinds Web Help Desk," highlighting the unauthenticated nature of the attack (Heise Online). The Canadian Centre for Cyber Security (CCCS) issued a security advisory (AV26-549) referencing the vulnerability (CCCS Advisory). Social media activity was limited, with brief mentions on Bluesky and Mastodon/Infosec.exchange, reflecting moderate community interest given the lack of active exploitation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."