Published on September 19, 2026

SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE


Severity
High

Detail

SolarWinds has released security updates to address a high-severity vulnerability in Access Rights Manager (ARM) that could allow an unauthenticated remote attacker to achieve remote code execution (RCE). Tracked as CVE-2026-28326, the vulnerability carries a CVSS score of 8.8 (High) and affects SolarWinds Access Rights Manager 2026.2 and earlier versions.

The vulnerability stems from a hard-coded static key within SolarWinds Access Rights Manager. Under exploitable conditions, an attacker who does not have valid credentials could leverage the static key to execute arbitrary code remotely on the affected ARM server. Successful exploitation could potentially provide an attacker with unauthorized control of the affected server and may expose sensitive identity and access-management data handled by the application.

The vulnerability was discovered and reported by security researcher Kai Huang of Armadin. SolarWinds has addressed the issue in Access Rights Manager 2026.2.1, released on September 17, 2026. SolarWinds’ advisory does not indicate that CVE-2026-28326 has been exploited in the wild. Organizations should nevertheless prioritize remediation because the vulnerability provides an unauthenticated attack path to remote code execution.

Access Rights Manager is used for managing permissions and access across environments including Active Directory. A successful compromise of an ARM server could therefore have implications for the confidentiality and integrity of identity and access-management information.

CVE IDSummaryCVSS Score
CVE-2026-28326A hard-coded static key vulnerability in SolarWinds Access Rights Manager could enable an unauthenticated remote attacker to execute arbitrary code on the affected system. SolarWinds classifies the vulnerability as an unauthenticated remote code execution vulnerability.8.8 (High)

Affected Products

The vulnerability affects:

  • SolarWinds Access Rights Manager 2026.2
  • SolarWinds Access Rights Manager versions earlier than 2026.2.1

SolarWinds addressed CVE-2026-28326 in Access Rights Manager 2026.2.1.

Recommendation

Organizations using SolarWinds Access Rights Manager are strongly advised to perform the following actions:

  • Upgrade Access Rights Manager to version 2026.2.1 or later.
  • Prioritize remediation for ARM servers that are accessible from untrusted or broad network segments.
  • Review authentication, application and server logs for suspicious or unexpected activity.
  • Investigate unexpected processes, command execution or modifications on ARM servers.
  • Review privileged accounts and permissions associated with the affected ARM infrastructure.
  • If compromise is suspected, isolate the affected server and perform a forensic investigation.
  • Consider rotating credentials and secrets accessible from a potentially compromised ARM server.

SolarWinds confirms that ARM 2026.2.1 specifically fixes CVE-2026-28326.

Source

https://thehackernews.com/2026/09/solarwinds-patches-arm-hard-coded-key.html