Skip to content
Threat Feed
high advisory

Unauthenticated Remote Code Execution in SolarWinds Access Rights Manager

CVE-2026-28326 is a critical remote code execution vulnerability in SolarWinds Access Rights Manager resulting from the use of a hardcoded static key, allowing unauthenticated attackers to execute arbitrary code.

CVE search metadata

CVE search record: CVE-2026-28326. Severity: high. CVSS: 8.8. KEV: no. Product: Access Rights Manager. Brief: Unauthenticated Remote Code Execution in SolarWinds Access Rights Manager. Brief link: https://feed.craftedsignal.io/briefs/2026-09-solarwinds-arm-rce/

SolarWinds Access Rights Manager is affected by a critical remote code execution vulnerability, tracked as CVE-2026-28326. The vulnerability arises from the implementation of a hardcoded static cryptographic key within the application. This flaw enables an unauthenticated attacker to bypass authentication mechanisms and execute arbitrary code on the underlying host. Given that Access Rights Manager typically operates with high-privileged service accounts to manage directory and file permissions across an organization, successful exploitation poses a severe risk of full environment compromise. Organizations utilizing SolarWinds Access Rights Manager on Windows Server platforms are urged to review security advisories from SolarWinds for patch availability and mitigation guidance, as this vulnerability provides a direct pathway for initial access and execution without requiring valid credentials.

Impact

Successful exploitation allows unauthenticated attackers to achieve remote code execution on the target Windows Server hosting the Access Rights Manager software. Because the application manages sensitive access controls, compromised instances could lead to unauthorized privilege escalation, exfiltration of directory services data, and persistent access across the enterprise network.

Recommendation

Prioritize the identification of all internet-facing or internal SolarWinds Access Rights Manager instances. Monitor for security updates provided by SolarWinds and apply patches as soon as they are released. Ensure that service accounts utilized by Access Rights Manager follow the principle of least privilege to contain potential blast radiuses.


Immediate actions

Inventory all instances of SolarWinds Access Rights Manager and verify current version.

IT Operations 24h

Mitigations

Apply vendor-supplied security patches to remediate CVE-2026-28326.

immediate IT Operations

CVE-2026-28326