ZeroHour

CVE-2026-28326

moderate

Unauthenticated RCE in SolarWinds Access Rights Manager via hardcoded static key

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

SolarWinds Access Rights Manager (ARM) contains an unauthenticated remote code execution flaw caused by a hardcoded static cryptographic key (CWE-321). An attacker who can reach the ARM service from an adjacent network, as reflected in the CVSS attack vector, can abuse the static key to bypass authentication and execute code without any user interaction or credentials. Successful exploitation yields high-impact code execution on the ARM server, which typically holds privileged Active Directory and service credentials, creating significant lateral-movement risk. Organizations running ARM on-premises, most commonly mid-size and large enterprises managing file-server and AD permissions, are affected. No public proof-of-concept is known, the issue is not on the CISA KEV list, and there are no confirmed reports of exploitation in the wild.

What to do: Upgrade SolarWinds Access Rights Manager to the fixed release identified in the SolarWinds security advisory (specific fixed version not stated in the available data). Until patched, restrict network access to the ARM server to dedicated management segments or VPN, since exploitation requires adjacent network access, and monitor ARM hosts for unexpected processes and outbound connections. Because ARM stores privileged directory credentials, treat any suspected compromise as potential domain compromise and rotate the credentials it manages.

Affected
SolarWinds Access Rights Manager
Estimated exposure
moderate≈10,000–100,000 on-premises installations worldwide (order-of-magnitude estimate) — SolarWinds has a very large enterprise customer base, but ARM is a specialized on-premises Active Directory/file-server permissions tool typically deployed on one or a few internal Windows servers per organization with few internet-facing…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability. The issue stems from a hardcoded static key.

Weakness
CWE-321
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

SolarWinds security advisory (AV26-941)

Canadian Cyber Centre alerts on unauthenticated RCE vulnerability CVE-2026-28326 in SolarWinds Access Rights Manager before 2026.2.

The Canadian Centre for Cyber Security issued advisory AV26-941 for an unauthenticated remote code execution vulnerability, CVE-2026-28326, affecting SolarWinds Access Rights Manager versions prior to 2026.2. Administrators are encouraged to review the provided links and apply updates as they become available.