CVE-2026-28299
SolarWinds Web Help Desk vulnerability analysis and mitigation

Overview

CVE-2026-28299 is a denial-of-service vulnerability in SolarWinds Web Help Desk that allows unauthenticated remote attackers to crash the server by triggering a memory exhaustion condition. It affects SolarWinds Web Help Desk version 2026.1 and all previous versions; the fixed release is version 2026.2. The vulnerability was published on June 2, 2026, with Tenable credited for responsible disclosure. It carries a CVSS v3.1 base score of 8.2 (High) (SolarWinds Advisory, GitHub Advisory).

Technical details

The root cause is classified as CWE-770 (Allocation of Resources Without Limits or Throttling), meaning the application fails to impose restrictions on the size or number of resources it allocates in response to incoming requests. An unauthenticated attacker can exploit this over the network with low complexity and no user interaction by sending crafted requests that cause the server to allocate memory without bound, ultimately exhausting available memory and crashing the Web Help Desk service. No specific technical write-up or proof-of-concept code has been publicly released as of the time of this report (SolarWinds Advisory, GitHub Advisory).

Impact

Successful exploitation results in a complete loss of availability for the Web Help Desk server, causing it to crash due to memory exhaustion and disrupting IT support operations for all users relying on the service. There is a low integrity impact noted in the CVSS vector, though the primary consequence is a denial of service. Confidentiality is not impacted, and there is no evidence of lateral movement potential or data exposure risk associated with this vulnerability (SolarWinds Advisory, GitHub Advisory).

Indicators of compromise

  • Network: Anomalous high-volume or malformed HTTP/HTTPS requests to the Web Help Desk server from unexpected source IPs, particularly requests that do not follow normal user interaction patterns.
  • System Resources: Sudden and sustained spike in memory consumption on the Web Help Desk host, potentially visible in OS-level monitoring tools (e.g., Task Manager, top, or performance counters), leading up to a service crash.
  • Logs: Web Help Desk application logs or system event logs showing out-of-memory errors, JVM heap exhaustion messages, or unexpected service termination events around the time of the crash.
  • Service: Unexpected restarts or crashes of the WHD backend service (WHD backend or equivalent managed service), particularly if recurring in a short timeframe.

Mitigation and workarounds

SolarWinds has released a fix in SolarWinds Web Help Desk 2026.2, and all users running version 2026.1 or earlier should upgrade immediately (SolarWinds Advisory, WHD 2026.2 Release Notes). As a temporary workaround prior to patching, administrators should implement network-level access controls (e.g., firewall rules, VPN requirements) to restrict which hosts can reach the Web Help Desk service, reducing the attack surface for unauthenticated network-based exploitation. Monitoring server memory utilization for signs of abnormal consumption can help detect exploitation attempts early.

Community reactions

Heise Online covered the vulnerability with an article titled "Attackers can disable SolarWinds Web Help Desk," highlighting the unauthenticated nature of the attack (Heise Online). The Canadian Centre for Cyber Security (CCCS) issued a security advisory (AV26-549) referencing the vulnerability (CCCS Advisory). Social media activity was limited, with brief mentions on Bluesky and Mastodon/Infosec.exchange, reflecting moderate community interest given the lack of active exploitation.

Additional resources


SourceThis report was generated using AI

Related SolarWinds Web Help Desk vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-40554CRITICAL9.8
  • SolarWinds Web Help Desk logoSolarWinds Web Help Desk
  • cpe:2.3:a:solarwinds:web_help_desk
NoYesJan 28, 2026
CVE-2025-40553CRITICAL9.8
  • SolarWinds Web Help Desk logoSolarWinds Web Help Desk
  • cpe:2.3:a:solarwinds:web_help_desk
NoYesJan 28, 2026
CVE-2025-40552CRITICAL9.8
  • SolarWinds Web Help Desk logoSolarWinds Web Help Desk
  • cpe:2.3:a:solarwinds:web_help_desk
NoYesJan 28, 2026
CVE-2025-40551CRITICAL9.8
  • SolarWinds Web Help Desk logoSolarWinds Web Help Desk
  • cpe:2.3:a:solarwinds:web_help_desk
YesYesJan 28, 2026
CVE-2026-28299HIGH7.5
  • SolarWinds Web Help Desk logoSolarWinds Web Help Desk
  • cpe:2.3:a:solarwinds:web_help_desk
NoYesJun 02, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management