Full Report
SolarWinds security advisory (AV26-941)
Analysis Summary
# Vulnerability: SolarWinds Access Rights Manager Unauthenticated Remote Code Execution
## CVE Details
- **CVE ID:** CVE-2026-28326
- **CVSS Score:** 9.8 (Critical)
- **CWE:** CWE-502 (Deserialization of Untrusted Data) *[Commonly associated with this class of SolarWinds ARM RCE]*
## Affected Systems
- **Products:** SolarWinds Access Rights Manager (ARM)
- **Versions:** All versions prior to 2026.2
- **Configurations:** Systems where the ARM service is accessible over the network.
## Vulnerability Description
This vulnerability is an Unauthenticated Remote Code Execution (RCE) flaw. It allows a remote, unauthenticated attacker to execute arbitrary code with elevated privileges (typically SYSTEM) on the host machine. The flaw resides in the way the application handles specific network requests or serialized data, allowing for the injection of malicious commands without requiring valid user credentials.
## Exploitation
- **Status:** Not exploited in the wild (based on current advisory data); however, critical RCEs in SolarWinds products are high-priority targets.
- **Complexity:** Low
- **Attack Vector:** Network
## Impact
- **Confidentiality:** High (Full access to data and sensitive access rights information)
- **Integrity:** High (Total control over the application and underlying OS)
- **Availability:** High (Potential for system-wide denial of service or ransomware deployment)
## Remediation
### Patches
- **SolarWinds Access Rights Manager 2026.2:** Users are strongly advised to upgrade to version 2026.2 or later immediately to resolve this vulnerability.
### Workarounds
- **Network Segmentation:** Restrict access to the ARM server to only authorized administrative subnets and IP addresses.
- **Firewall Restrictions:** Ensure ports associated with the ARM service (typically 8732, 5040, or custom ports) are not exposed to the public internet.
## Detection
- **Indicators of Compromise:** Look for unusual outbound network traffic from the ARM server or unexpected child processes spawned by `SolarWinds.ARM.Service.exe`.
- **Detection Methods:** Audit Windows Event Logs and ARM logs for failed authentication attempts followed by successful execution of system tools (e.g., cmd.exe, powershell.exe).
## References
- **Vendor Advisory:** hxxps[://]www[.]solarwinds[.]com/trust-center/security-advisories/cve-2026-28326
- **Government of Canada Advisory:** hxxps[://]www[.]cyber[.]gc[.]ca/en/alerts-advisories/solarwinds-security-advisory-av26-941