highZero-Day

SolarWinds Access Rights Manager Hard-Coded Key RCE (CVE-2026-28326)

First seen Sep 21, 2026 · Updated Sep 21, 2026 · CVSS 8.8

solarwindsarmrcehard-coded-keyunauthenticatedidentity-managementprivileged-accesspatch-available

SolarWinds disclosed and patched a high-severity flaw in its Access Rights Manager (ARM) product caused by a hard-coded cryptographic key, which could allow unauthenticated attackers to achieve remote code execution. The vulnerability affects all ARM versions 2026.2 and prior and carries a CVSS score of 8.8, making unpatched instances a critical target for exploitation.

Technical Analysis

CVE-2026-28326 stems from a hard-coded cryptographic key embedded within SolarWinds Access Rights Manager, which can be leveraged by an unauthenticated attacker to forge trusted payloads or tokens and achieve remote code execution on the host. Because ARM is used to manage and audit user permissions and access rights across enterprise directories (e.g., Active Directory, file servers, Exchange), successful exploitation could grant an attacker broad control over identity and access management infrastructure. The flaw affects all versions 2026.2 and prior, indicating the hard-coded key issue likely persisted across multiple release cycles. Given ARM's typical deployment on Windows servers with elevated privileges over directory services, exploitation could serve as a pivot point for lateral movement and privilege escalation across the network. Organizations running AI agents or automation pipelines that authenticate against Active Directory or use ARM-managed service accounts for tool access could see their agent credentials and API keys exposed or hijacked if the underlying identity infrastructure is compromised, warranting inclusion under agent-relevant risk.

Affected Systems

SolarWinds Access Rights Manager (ARM) version 2026.2 and all prior versions, typically deployed on Windows Server environments integrated with Active Directory, file servers, Exchange, and SharePoint for access rights auditing and management.

Indicators of Compromise

  • No specific IOCs published at time of disclosure; vulnerability disclosed via SolarWinds security advisory referencing CVE-2026-28326.

Remediation Steps

  1. 1

    Apply Vendor Patch

    Upgrade SolarWinds Access Rights Manager to the latest patched version provided by SolarWinds that remediates CVE-2026-28326.

  2. 2

    Restrict Network Exposure

    Limit network access to ARM management interfaces to trusted internal networks and VPNs; ensure the service is not exposed to the public internet.

  3. 3

    Rotate Cryptographic Keys and Credentials

    After patching, rotate any keys, service account credentials, and API keys associated with ARM and connected directory services in case they were exposed prior to remediation.

  4. 4

    Audit Access Logs

    Review ARM and Active Directory logs for anomalous authentication attempts, privilege escalations, or unauthorized configuration changes indicative of exploitation attempts.

  5. 5

    Segment Identity Management Infrastructure

    Ensure ARM and other identity/access management tools are segmented from general enterprise networks and agent/automation environments to limit blast radius.

CVE / Advisory IDs

CVE-2026-28326

Industries Most Exposed

IT/TechnologyFinancial ServicesHealthcareGovernmentEnterprise/Corporate ITManaged Service Providers

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.