Full Report
SolarWinds has released security updates to address a high-severity flaw in Access Rights Manager (ARM) that, if successfully exploited, could lead to an unauthenticated remote code execution vulnerability. The vulnerability, tracked as CVE-2026-28326, is rated 8.8 out of 10.0 on the CVSS scoring system. The issue affects all versions of Access Rights Manager 2026.2 and prior. "SolarWinds
Analysis Summary
# Vulnerability: SolarWinds Access Rights Manager (ARM) Hard-Coded Static Key RCE
## CVE Details
- **CVE ID:** CVE-2026-28326
- **CVSS Score:** 8.8 (High)
- **CWE:** Hard-coded Cryptographic Key (Implicit based on "hard-coded static key" description)
## Affected Systems
- **Products:** SolarWinds Access Rights Manager (ARM)
- **Versions:** All versions 2026.2 and prior.
- **Configurations:** Systems running the Access Rights Manager service accessible over the network.
## Vulnerability Description
This high-severity flaw exists within SolarWinds Access Rights Manager (ARM) due to the use of a hard-coded static cryptographic key. An unauthenticated remote attacker could leverage this static key to bypass security mechanisms, potentially leading to Remote Code Execution (RCE) on the affected server.
## Exploitation
- **Status:** Not currently reported as exploited in the wild.
- **Complexity:** Low to Medium (Exploitation relies on the retrieval/knowledge of the hard-coded key).
- **Attack Vector:** Network (Unauthenticated).
## Impact
- **Confidentiality:** High (Potential for full system access).
- **Integrity:** High (Attacker can execute arbitrary code).
- **Availability:** High (Attacker can modify or disable the service).
## Remediation
### Patches
- **ARM 2026.2.1:** SolarWinds has released version 2026.2.1 to address this specific vulnerability. Users are urged to upgrade immediately.
### Workarounds
- No specific workarounds were provided in the article. The primary recommendation is the installation of the security patch.
- General best practices include restricting network access to ARM management interfaces to trusted IP addresses only.
## Detection
- **Indicators of Compromise:** Monitor for unusual network traffic originating from the ARM server or unexpected administrative actions within the ARM console.
- **Detection methods and tools:** Audit system logs for unauthorized access attempts or suspicious service crashes. Ensure vulnerability scanners are updated to check for outdated ARM versions.
## References
- SolarWinds Trust Center: hxxps[://]www[.]solarwinds[.]com/trust-center/security-advisories/cve-2026-28326
- SolarWinds ARM 2026.2.1 Release Notes: hxxps[://]documentation[.]solarwinds[.]com/en/success_center/arm/content/release_notes/arm_2026-2-1_release_notes[.]htm
- The Hacker News Article: hxxps[://]thehackernews[.]com/2026/09/solarwinds-patches-arm-hard-coded-key[.]html