SolarWinds Access Rights Manager Hard-Coded Key RCE (CVE-2026-28326)
First seen Sep 21, 2026 · Updated Sep 21, 2026 · CVSS 8.8
SolarWinds disclosed and patched a high-severity flaw in its Access Rights Manager (ARM) product caused by a hard-coded cryptographic key, which could allow unauthenticated attackers to achieve remote code execution. The vulnerability affects all ARM versions 2026.2 and prior and carries a CVSS score of 8.8, making unpatched instances a critical target for exploitation.
Technical Analysis
CVE-2026-28326 stems from a hard-coded cryptographic key embedded within SolarWinds Access Rights Manager, which can be leveraged by an unauthenticated attacker to forge trusted payloads or tokens and achieve remote code execution on the host. Because ARM is used to manage and audit user permissions and access rights across enterprise directories (e.g., Active Directory, file servers, Exchange), successful exploitation could grant an attacker broad control over identity and access management infrastructure. The flaw affects all versions 2026.2 and prior, indicating the hard-coded key issue likely persisted across multiple release cycles. Given ARM's typical deployment on Windows servers with elevated privileges over directory services, exploitation could serve as a pivot point for lateral movement and privilege escalation across the network. Organizations running AI agents or automation pipelines that authenticate against Active Directory or use ARM-managed service accounts for tool access could see their agent credentials and API keys exposed or hijacked if the underlying identity infrastructure is compromised, warranting inclusion under agent-relevant risk.
Affected Systems
SolarWinds Access Rights Manager (ARM) version 2026.2 and all prior versions, typically deployed on Windows Server environments integrated with Active Directory, file servers, Exchange, and SharePoint for access rights auditing and management.
Indicators of Compromise
- No specific IOCs published at time of disclosure; vulnerability disclosed via SolarWinds security advisory referencing CVE-2026-28326.
Remediation Steps
- 1
Apply Vendor Patch
Upgrade SolarWinds Access Rights Manager to the latest patched version provided by SolarWinds that remediates CVE-2026-28326.
- 2
Restrict Network Exposure
Limit network access to ARM management interfaces to trusted internal networks and VPNs; ensure the service is not exposed to the public internet.
- 3
Rotate Cryptographic Keys and Credentials
After patching, rotate any keys, service account credentials, and API keys associated with ARM and connected directory services in case they were exposed prior to remediation.
- 4
Audit Access Logs
Review ARM and Active Directory logs for anomalous authentication attempts, privilege escalations, or unauthorized configuration changes indicative of exploitation attempts.
- 5
Segment Identity Management Infrastructure
Ensure ARM and other identity/access management tools are segmented from general enterprise networks and agent/automation environments to limit blast radius.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.