SolarWinds Access Rights Manager CVE-2026-28326: Hard-Coded Key to Unauth RCE

By George Bailey   Published: 09/20/26   Updated: 09/20/26   2 min read

Access Rights Manager exists to tell you who can touch what. A hard-coded static key in every install turns that trust map into an unauthenticated remote code execution problem — and the fix is a same-week upgrade to 2026.2.1.

What happened

On September 17, 2026, SolarWinds published an advisory for CVE-2026-28326: Access Rights Manager is affected by an unauthenticated remote code execution vulnerability stemming from a hard-coded static cryptographic key (CWE-321). The issue affects ARM 2026.2 and all previous versions. Fixed software: ARM 2026.2.1. CVSS 3.1 8.8 (AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). Credit: Kai Huang, Armadin.

SolarWinds reports no evidence of exploitation in the wild as of the advisory. The advisory does not detail which protocol object the key protects — operators should treat “unauthenticated RCE + static key” as enough to prioritize without waiting for a public write-up.

Why it matters

A hard-coded key extracted once works on the next server, and the one after that. ARM’s job is identity and entitlement visibility across directories and file shares — landing there is an unusually efficient place for an attacker to learn (and then abuse) who can reach what. Adjacent-network unauthenticated RCE on that class of product is a Monday change-window item, not a quarterly patch bag.

What to do first

Details

Hunt / verify

Sources

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.