CVE-2026-28326 PUBLISHED

SolarWinds Access Rights Manager Unauthenticated Remote Code Execution Vulnerability

Assigner: SolarWinds
Reserved: 26.02.2026 Published: 17.09.2026 Updated: 18.09.2026

SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability. The issue stems from a hardcoded static key.

Metrics

CVSS Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 8.8

Product Status

Vendor SolarWinds
Product Access Rights Manager
Versions Default: unaffected
  • Version 2026.2 and all previous versions is affected

Solutions

SolarWinds recommends customers to upgrade to Access Rights Manager version 2026.2.1 as soon as is practical.

Credits

  • Kai Huang from Armadin reporter

References

Problem Types

  • CWE-321: Use of Hard-coded Cryptographic Key CWE

Impacts

  • CAPEC-242 Code Injection