Signature Optional - Analysis of CVE-2026-28323
#bishopfox
SolarWinds Web Help Desk treated SAML signature verification as optional and skipped every other validation the spec requires. Bishop Fox confirmed the full exploit end to end: one forged POST request, no credentials, full session takeover. Here is the root cause, the fix, and how to detect it.
via BishopFox Blog
Post #1660
244