ZeroHour
Product

Access Rights Manager

2 mentions in 7 days · 2 in 30 days · 2 total · first seen · last

Timeline

SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE

SolarWinds patched CVE-2026-28326 (CVSS 8.8), a hard-coded-key flaw enabling unauthenticated remote code execution in Access Rights Manager 2026.2 and prior.

SolarWinds released ARM 2026.2.1 on September 17, 2026 to fix CVE-2026-28326, an unauthenticated remote code execution flaw in Access Rights Manager caused by a hard-coded static key, reported by Armadin researcher Kai Huang. The company stated there is no evidence of exploitation in the wild. The same cycle resolved Web Help Desk issues CVE-2026-28323 (CVSS 9.8, SAML authentication bypass) and CVE-2026-28299 (CVSS 8.2, denial-of-service), plus 16 Serv-U flaws enabling privilege escalation, RCE, and administrator account creation.

SolarWinds security advisory (AV26-941)

Canadian Cyber Centre alerts on unauthenticated RCE vulnerability CVE-2026-28326 in SolarWinds Access Rights Manager before 2026.2.

The Canadian Centre for Cyber Security issued advisory AV26-941 for an unauthenticated remote code execution vulnerability, CVE-2026-28326, affecting SolarWinds Access Rights Manager versions prior to 2026.2. Administrators are encouraged to review the provided links and apply updates as they become available.

Related CVEs

  • Unauthenticated RCE in SolarWinds Access Rights Manager via hardcoded static key
    SolarWinds Access Rights Manager (ARM) contains an unauthenticated remote code execution flaw caused by a hardcoded static cryptographic key (CWE-321). An attacker who can reach the ARM service from an adjacent network, as reflected in the CVSS attack vector, can abuse the static key to bypass authentication and execute code without any user interaction or credentials. Successful exploitation yields high-impact code execution on the ARM server, which typically holds privileged Active Directory and service credentials, creating significant lateral-movement risk. Organizations running ARM on-premises, most commonly mid-size and large enterprises managing file-server and AD permissions, are affected. No public proof-of-concept is known, the issue is not on the CISA KEV list, and there are no confirmed reports of exploitation in the wild.
    · SolarWinds Access Rights Managermoderate
  • SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability.
    SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2.0 authentication method to be enabled.
    · solarwinds web help desk
  • SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to SMTP hijacking leading to arbitrary account takeover.
    SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to SMTP hijacking leading to arbitrary account takeover. The impact is lower in Windows deployments.
    · solarwinds serv-u
  • SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to elevate their privileges to a system administrator.
    SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to elevate their privileges to a system administrator. The impact is lower in Windows deployments.
    · solarwinds serv-u
  • SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution.
    SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution. Domain administrator access is required. The impact is lower in Windows deployments.
    · solarwinds serv-u
  • SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation.
    SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation. This issue requires domain administrator access. The impact is lower in Windows deployments.
    · solarwinds serv-u
  • SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation to a system administrator with t
    SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation to a system administrator with the ability to execute commands as the root user. This issue requires a domain account with administrator access. The impact is lower in Windows deployments.
    · solarwinds serv-u
  • SolarWinds Serv-U is affected by a broken access control vulnerability that allows a domain administrator to create system administrator accounts.
    SolarWinds Serv-U is affected by a broken access control vulnerability that allows a domain administrator to create system administrator accounts. The impact is lower in Windows deployments.
    · solarwinds serv-u
  • SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and write, which can then be used to escalate privil
    SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and write, which can then be used to escalate privileges and execute code as root. A domain administrator access is required, and the impact is lower in Windows installations.
    · solarwinds serv-u

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.