CVE-2026-28326

8.8

SolarWinds · Access Rights Manager

SolarWinds Access Rights Manager contains a vulnerability involving a hardcoded static cryptographic key, which allows an unauthenticated attacker to achieve remote code execution.

Executive summary

A critical remote code execution vulnerability in SolarWinds Access Rights Manager, caused by a hardcoded cryptographic key, poses a severe risk of total system compromise to affected environments.

Vulnerability

The application utilizes a hardcoded static cryptographic key, which enables an unauthenticated attacker to bypass security controls and execute arbitrary code on the host system.

Business impact

Successful exploitation of this vulnerability allows an attacker to gain full control over the affected SolarWinds Access Rights Manager instance. Given the CVSS score of 8.8, this represents a high-severity risk that could lead to complete data compromise, unauthorized administrative access, and significant operational disruption. Organizations relying on this software for identity and access management are at heightened risk of lateral movement and persistence by malicious actors.

Remediation

Immediate Action: Upgrade to SolarWinds Access Rights Manager version 2026.2.1 immediately to remove the vulnerable hardcoded key.

Proactive Monitoring: Review system and application logs for unusual execution patterns or unauthorized access attempts originating from internal network segments.

Compensating Controls: Restrict network access to the Access Rights Manager interface to only trusted administrative workstations, as the vulnerability is reachable via the adjacent network.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The presence of a hardcoded cryptographic key constitutes a fundamental security failure that cannot be mitigated by configuration changes alone. It is imperative that administrators prioritize the update to version 2026.2.1 across all deployments. Failure to patch this vulnerability leaves the environment exposed to potential remote code execution by any actor with network access to the application.

More SolarWinds CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources

Originally found and disclosed by Kai Huang from Armadin, per the CVE Program record.