SolarWinds Access Rights Manager RCE via Hardcoded Static Key
CVE-2026-28326 Published on September 17, 2026
SolarWinds Access Rights Manager Unauthenticated Remote Code Execution Vulnerability
SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability. The issue stems from a hardcoded static key.
Vulnerability Analysis
Attack Vector:
ADJACENT_NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
Weakness Type
Use of Hard-coded Cryptographic Key
The use of a hard-coded cryptographic key significantly increases the possibility that encrypted data may be recovered.
Products Associated with CVE-2026-28326
Want to know whenever a new CVE is published for SolarWinds Access Rights Manager? stack.watch will email you.