CVE-2026-28326: SolarWinds Access Rights Manager Unauthenticated Remote Code Execution Vulnerability
Published Sep 17, 2026
·Updated
SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability. The issue stems from a hardcoded static key.
Affected Software
1 affected component
SolarWinds Access Rights Manager
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SolarWinds Access Rights Managerto a version that resolves this vulnerability.Fixed in 2026.2.1
Event History
Sep 17, 2026
CVE Published
via MITRE·04:30 PM
Data Sourced
via MITRE·04:30 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
No authentication or prior privileges are required. The vector is adjacent network access, so the attacker must be able to reach the affected service from a connected network segment.
2
What is the potential impact of successful exploitation?
Successful exploitation can result in remote code execution with high impact to confidentiality, integrity, and availability.
3
What is the underlying cause of the vulnerability?
The reported issue stems from a hardcoded static key.