SolarWinds SAML Bypass: The IT Ticketing Supply-Chain Path
A CVSS 9.8 SAML bypass in SolarWinds Web Help Desk — same 3X pattern. What IT ticketing tool runs your broker-portal SSO?
A CVSS 9.8 authentication bypass in SolarWinds Web Help Desk — disclosed this week, requiring only that the SAML 2.0 sign-in method is enabled — is the kind of finding that, in isolation, doesn’t move a portfolio. Most enterprises run SolarWinds Web Help Desk behind a single sign-in that goes through Azure AD or Okta. The SAML bypass is the kind of finding that gets fixed in a patch and forgotten. But the disclosure lands at the same moment the underwriter is reading a broker email about the same vendor. The pattern is what matters: a single IT ticketing tool with a sign-in bypass becomes, for the duration of the patch window, an authentication-bypass event across every customer whose broker-portal or self-service portal federates through SolarWinds SAML. The underwriter’s question is not “do you use SolarWinds Web Help Desk?” — it is “which IT ticketing tool runs your broker-portal or self-service SSO, and is the SAML 2.0 sign-in path enabled?” That question determines whether the bypass hits the insured directly, or the insured’s broker-portal provider, or the insured’s customer-portal provider. The answer shifts the loss from a single tower to an aggregation event.
What happened
SolarWinds Web Help Desk ships with a SAML 2.0 sign-in method that allows an enterprise to federate the help-desk sign-in through an identity provider. The disclosed vulnerability bypasses that federation — an attacker who can reach the SolarWinds login endpoint can forge or replay a SAML assertion and gain access to the help-desk instance without holding valid credentials. The disclosed chain is short, the prerequisites are minimal (only that SAML 2.0 is enabled, which is the default for the integration), and the impact is full administrative access to the help-desk instance.
The finding lands in the same disclosure class as the recent Langflow and Plesk disclosures (CVSS 9.9 each): an enterprise IT component with a primary security control (SAML, in this case) that can be bypassed. The Plesk and Langflow findings are about code-execution paths that turn the vulnerable component into a beachhead for ransomware. The SolarWinds finding is about identity: the vulnerable component becomes a sign-in door, not a code-execution door. The two failure modes produce the same downstream loss shape (a single event at a supplier, many insureds affected), but the SolarWinds one is a quieter failure — the attacker authenticates legitimately, sits in the system for weeks, and only the eventual activity pattern reveals the breach.
The SolarWinds vendor history matters here. The 2020 SolarWinds Orion supply-chain attack was a code-execution beachhead in a network management tool — an IT operations component. The 2026 SolarWinds Web Help Desk finding is an authentication bypass in a help-desk tool — an IT support component. Both are IT-administration surface. Both are widely deployed. Both are operated by IT teams, not security teams, so the security control depth is shallower than the rest of the enterprise. The pattern is the same: IT administration surface, weak identity controls, supply-chain aggregation risk.
Why this matters for insurance
The standard cyber tower assumes a single-enterprise perimeter: one insured, one set of controls, one sublimit. The SolarWinds SAML bypass, like the Langflow RCE and Plesk SQL injection, breaks that model in three places.
First, the IT ticketing tool sits in the broker-portal or self-service portal SSO path. Most enterprises don’t use SolarWinds Web Help Desk as their primary IDP — they federate to it from Azure AD or Okta. The SAML bypass is irrelevant to the insured’s primary IDP, but it’s directly relevant to the IT ticketing tenant that handles the insured’s IT support workflows — which includes the broker-portal, the self-service renewals, the in-app password reset emails. A bypass in the IT ticketing tool compromises the support workflow, not the IDP, but the compromised workflow handles high-value authentication events (password reset links, MFA factor changes, broker-portal SSO transitions). The loss is credential-adjacent, not the SSO itself.
Second, the help-desk instance is a single tenant across the enterprise. A single SolarWinds Web Help Desk instance is typically shared across the enterprise — every department’s IT support goes through it. A bypass in that instance is a bypass of every ticket the IT team has ever handled: every user’s email, every password reset, every MFA factor change, every system access request. The aggregation tail is the enterprise’s IT history.
Third, the IT ticketing tool is itself a third-party supplier. Most enterprises don’t operate the help-desk tool; the IT team does, but the tool is SaaS or vendor-supported. A bypass at the tool is a third-party compromise, with the same loss-tail shape as the Klue – Salesforce breach aggregation analysis and the AI tool RCE post. One tool, many insureds (if the carrier’s book has many customers using the same IT ticketing vendor), one patch window.
These three properties — IT-administration surface, tenant-shared instance, third-party supplier — are why the same vendor keeps reappearing in supply-chain disclosures. The underwriting profession has been catching up to payment processors and SaaS billing tools. IT ticketing is the next surface that needs the same kind of systematic vendor-concentration discipline.
The IT ticketing surface, in business language
A carrier that has fifty insureds all using the same IT ticketing vendor faces the same kind of correlated loss that a SaaS-billing aggregator faces when its authentication breaks. The difference is that IT ticketing is typically outside the security questionnaire: the insured’s CISO knows what IDP they use, but doesn’t necessarily know what IT ticketing tool the IT team uses. The broker knows even less. The underwriter’s most direct path to surface this is the renewal question: “which IT ticketing tool does this insured use, and does it federate to your broker-portal or self-service portal through SAML 2.0?”
The underwriter who asks that question systematically will catch the next SolarWinds disclosure at the questionnaire level. The underwriter who doesn’t will read the disclosure after the fact, on a Friday afternoon, and find that the broker portal has been compromised for three weeks. The underwriter-side of the supply-chain problem is almost entirely a question-asking problem.
For brokers: the conversation is not “do you use SolarWinds” — it is “what is the IT ticketing tool, and is the SAML 2.0 sign-in path enabled on the broker-portal integration?” Document the answer in writing. The carriers that win the next renewal cycle will be the ones that can answer the IT-ticketing SSO question accurately.
Implications for coverage and underwriting
The SolarWinds SAML bypass, like the Langflow and Plesk findings, forces four renewal-cycle questions that most submissions are not yet asking.
First, IT ticketing vendor inventory. Map the insured’s IT ticketing vendor before quoting: which tool, which version, which sign-in methods are enabled (SAML 2.0, OIDC, local). The carrier’s panel of approved IT ticketing tools is not yet standard; underwriters should ask for the insured’s own list.
Second, sublimit for IT-administration-surface compromise. The loss shape from a SAML bypass in the help-desk tool is not a typical cyber-incident loss: it’s a credential-adjacent loss, with potential downstream lateral movement. Re-underwrite the sublimit against the insured’s IT-ticketing-vendor concentration, not just the insured’s own IDP.
Third, vendor-side incident attribution. When the IT ticketing vendor discloses a breach, the carrier’s exposure is correlated across the insured book. The patch window is the carrier’s tail window. Renewal questions should establish which vendor disclosures the insured monitors, and which the insured does not.
Fourth, the broker-portal and self-service-portal SSO path. A carrier that runs its own broker-portal or self-service portal federates through the insured’s IDP, but also through the insured’s IT ticketing tool. The IT-ticketing path is the supply-chain risk the underwriter should be asking about.
Actionable recommendations
- Underwriters: at Q3/Q4 2026 renewal, ask the insured’s IT ticketing vendor explicitly. Map the answers against the disclosed CVEs in the [OpenCTI snapshot] stream (see our coverage of the Langflow RCE class) stream. The book that has the same IT ticketing vendor across multiple insureds is the book with the aggregation tail.
- Brokers: walk the client through the IT-ticketing story explicitly. The conversation is not “do you use SolarWinds” — it is “what is the IT ticketing tool, and is the SAML 2.0 sign-in path enabled on the broker-portal integration?” Document the answer in writing. The carriers that win the next renewal cycle will be the ones that can answer the IT-ticketing SSO question accurately.
- Insured CISOs and IT security: treat the IT ticketing tool as a first-class identity surface. Inventory the tools, check the SAML configuration, monitor the vendor’s CVE stream, and segment the IT ticketing tenant from the rest of the SSO graph. The tool that handles the help desk is the tool that handles the password reset.
- Risk managers at carriers: build a tier of “IT-ticketing-allowed” vendors with concentration caps. The same way payment processors became a known tier, IT-ticketing vendors will become a known tier over the next 24 months. The carriers that get ahead of the curve on the underwriting side will price this cycle correctly.
Takeaway
The SolarWinds SAML bypass, like the Langflow and Plesk findings before it, is not the right level to read the risk at. The right level is the surface underneath: the IT-administration tier, the SAML path, the IT ticketing tool that the rest of the SSO graph trusts. For underwriters, the right question is not “do you use SolarWinds” but “what is the IT ticketing tool, and is the SAML 2.0 sign-in path enabled.” The carrier that prices the IT-ticketing SAML cycle correctly will out-perform the carrier that prices the CVSS 9.8 alone — for the same reason the carrier that priced payment-processor concentration correctly out-performed the carrier that priced retail breach likelihood alone.
Michael Guiao Michael Guiao gründete Resiliently AI und schreibt Resiliently. Er hat CISM, CCSP, CISA und DPO-Zertifizierungen — aber sie verfallen lassen, denn im Zeitalter von KI ist Wissen billig. Worauf es ankommt, ist Urteilskraft — und die kommt aus acht Jahren Praxis bei Zurich, Sompo, AXA und PwC.
Go deeper with premium cyber risk reports
Professional-grade analysis, NIS2 compliance guides, and threat intelligence — used by underwriters across Europe.
Professional
Full platform — continuous monitoring, API access, white-label reports
Everything in Starter plus professional tools
Upgrade Now →Free NIS2 Compliance Checklist
Get the free 15-point PDF checklist + NIS2 compliance tips in your inbox.
No spam. Unsubscribe anytime. Privacy Policy
blog.featured
AI Tooling RCE: The Sublimit Layer Underwriters Rarely Underwrite
9 min read
SolarWinds SAML Bypass: The IT Ticketing Supply-Chain Path
9 min read
AM Best and S&P Flag Cyber Pricing Risks: What Underwriters Should Do at Renewal
7 min read
One Salesforce Integration Breach Just Hit 200 Cyber Insureds
8 min read
Premium Report
2026 Cyber Risk Landscape Report
24 pages of threat analysis, claims data, and underwriting implications for European cyber insurance.
View Reports →Verwandte Artikel
The Five Toxic Powers of Agentic AI — What Underwriters Need to Know
Agentic AI introduces five double-edged powers that create toxic risk combinations. Here's how underwriters, brokers, and CISOs should assess the threat.
Agentic Security: What Underwriters Need to Know in 2026
Autonomous AI agents are entering production at scale — and they bring a completely new attack surface that traditional cyber insurance questionnaires weren't designed to capture.
An AI Agent Deleted a Startup's Production Database — Can You Insure Against That?
PocketOS lost its production database to a Cursor AI agent in 9 seconds. The incident exposes a gap in cyber insurance that most policies don't cover: AI-caused operational destruction with no external attacker.