A static key in SolarWinds ARM lets outsiders run code remotely

SolarWinds has patched a hard-coded key that let unauthenticated attackers run code in Access Rights Manager.

CSBadmin
1 Min Read

Teams running SolarWinds Access Rights Manager should install version 2026.2.1 now, not at the next maintenance window. The release closes a hard-coded static key that let code run on the server with no credentials at all.

An advisory published on September 17 records the bug as CVE-2026-28326, scored 8.8, and lists every release up to and including 2026.2 as affected. Kai Huang of Armadin reported it. SolarWinds says nothing about exploitation in the wild, which is the one piece of good news here.

Why this one is worth the interruption

Access Rights Manager maps who can reach what across Active Directory, file shares and cloud applications. A foothold there is a foothold in the identity picture.

The same maintenance round addressed a long list elsewhere in the portfolio. Sixteen Serv-U flaws were patched, spanning privilege escalation, remote code execution and administrator account creation. Web Help Desk received a fix for a SAML bypass rated 9.8, CVE-2026-28323, that opens when SAML 2.0 sign-in is switched on, plus a memory exhaustion bug at 8.2.

No workaround was published. Confirm the version your inventory actually reports, and check whether any Access Rights Manager interface answers from the internet.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.