Remote Code Execution Vulnerability in SolarWinds Access Rights Manager
CVE-2026-28326
Key Information:
- Vendor
Solarwinds
- Status
- Vendor
- CVE Published:
- 17 September 2026
Badges
What is CVE-2026-28326?
CVE-2026-28326 is a critical vulnerability identified in SolarWinds Access Rights Manager, a software solution designed to help organizations manage and enforce access control policies, ensuring that users have the appropriate permissions for various systems and data. The vulnerability arises from a hardcoded static key within the application, which poses a significant risk as it allows unauthenticated users to perform remote code execution. If successfully exploited, malicious actors can gain control over the application and possibly the underlying network, leading to unauthorized access to sensitive information and compromising the integrity of the system.
Potential impact of CVE-2026-28326
-
Unauthorized Remote Access: The vulnerability permits attackers to execute code remotely without authentication, granting them the ability to manipulate system configurations and access confidential data, which can lead to severe data breaches.
-
System Compromise: By exploiting this vulnerability, attackers could deploy malicious payloads or malware, resulting in the full compromise of the affected systems, which could disrupt operations and hinder organizational productivity.
-
Reputational Damage: The fallout from a successful exploitation could extend beyond operational impacts, potentially damaging the organization's reputation and eroding customer trust. This is particularly critical for firms managing sensitive data or operating in regulated industries.
Affected Version(s)
Access Rights Manager 2026.2 and all previous versions
References
CVSS V3.1
Timeline
- π
Vulnerability started trending
Vulnerability published
Vulnerability Reserved