Remote Code Execution Vulnerability in SolarWinds Access Rights Manager
CVE-2026-28326

8.8HIGH

Key Information:

Vendor

Solarwinds

Vendor
CVE Published:
17 September 2026

Badges

πŸ”₯ Trending nowπŸ“ˆ TrendedπŸ“ˆ Score: 2,830

What is CVE-2026-28326?

CVE-2026-28326 is a critical vulnerability identified in SolarWinds Access Rights Manager, a software solution designed to help organizations manage and enforce access control policies, ensuring that users have the appropriate permissions for various systems and data. The vulnerability arises from a hardcoded static key within the application, which poses a significant risk as it allows unauthenticated users to perform remote code execution. If successfully exploited, malicious actors can gain control over the application and possibly the underlying network, leading to unauthorized access to sensitive information and compromising the integrity of the system.

Potential impact of CVE-2026-28326

  1. Unauthorized Remote Access: The vulnerability permits attackers to execute code remotely without authentication, granting them the ability to manipulate system configurations and access confidential data, which can lead to severe data breaches.

  2. System Compromise: By exploiting this vulnerability, attackers could deploy malicious payloads or malware, resulting in the full compromise of the affected systems, which could disrupt operations and hinder organizational productivity.

  3. Reputational Damage: The fallout from a successful exploitation could extend beyond operational impacts, potentially damaging the organization's reputation and eroding customer trust. This is particularly critical for firms managing sensitive data or operating in regulated industries.

Affected Version(s)

Access Rights Manager 2026.2 and all previous versions

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • πŸ“ˆ

    Vulnerability started trending

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kai Huang from Armadin
.