SolarWinds Access Rights Manager RCE via Hardcoded Static Key
CVE-2026-28326 Published on September 17, 2026

SolarWinds Access Rights Manager Unauthenticated Remote Code Execution Vulnerability
SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability. The issue stems from a hardcoded static key.

Vendor Advisory NVD

Vulnerability Analysis

Attack Vector:
ADJACENT_NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH

Weakness Type

Use of Hard-coded Cryptographic Key

The use of a hard-coded cryptographic key significantly increases the possibility that encrypted data may be recovered.


Products Associated with CVE-2026-28326

Want to know whenever a new CVE is published for SolarWinds Access Rights Manager? stack.watch will email you.

 

Affected Versions

SolarWinds Access Rights Manager Version 2026.2 and all previous versions is affected by CVE-2026-28326