Description
SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability. The issue stems from a hardcoded static key.
Published: 2026-09-17
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

SolarWinds Access Rights Manager suffers from an unauthenticated remote code execution flaw that arises because the application stores a hardcoded static key. This weakness means that an attacker who can reach the exposed interfaces can run arbitrary commands on the managed host without needing any credentials, potentially allowing full takeover of the system, data exfiltration, and persistence mechanisms. The violation is a cryptographic flaw (CWE-321) that directly undermines confidentiality, integrity, and availability of the affected environment.

Affected Systems

The vulnerability affects all installations of SolarWinds Access Rights Manager that were deployed before the release of version 2026.2.1. The CNA has identified the product name as Access Rights Manager and recommends that users upgrade to the 2026.2.1 release, which eliminates the hardcoded key and presumably fixes the code path that permits the exploit.

Risk and Exploitability

The vulnerability carries a CVSS score of 8.8, indicating a high severity. The EPSS score is reported as less than 1 %, suggesting a low probability of exploitation at present, and it is not listed in CISA’s KEV catalogue. Nevertheless, the attack path is likely to be remote over the network with no authentication required, so any exposed instance of the service could be targeted. Given the high impact and sufficient network exposure, the risk remains significant for organizations that have not applied the vendor’s patch yet.

Generated by OpenCVE AI on September 18, 2026 at 23:48 UTC.

Remediation

Vendor Solution

SolarWinds recommends customers to upgrade to Access Rights Manager version 2026.2.1 as soon as is practical.


OpenCVE Recommended Actions

  • Upgrade SolarWinds Access Rights Manager to version 2026.2.1 or later as soon as possible
  • Disable any unused management interfaces that expose the service to the network
  • Monitor system and network logs for anomalous execution attempts or unauthorized access attempts

Generated by OpenCVE AI on September 18, 2026 at 23:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Solarwinds
Solarwinds access Rights Manager
Vendors & Products Solarwinds
Solarwinds access Rights Manager

Thu, 17 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability. The issue stems from a hardcoded static key.
Title SolarWinds Access Rights Manager Unauthenticated Remote Code Execution Vulnerability
Weaknesses CWE-321
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Solarwinds Access Rights Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: SolarWinds

Published:

Updated: 2026-09-18T13:41:15.553Z

Reserved: 2026-02-26T14:46:41.521Z

Link: CVE-2026-28326

cve-icon Vulnrichment

Updated: 2026-09-18T13:32:29.999Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-17T17:16:39.960

Modified: 2026-09-18T19:07:38.320

Link: CVE-2026-28326

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T00:00:12Z

Weaknesses
  • CWE-321

    Use of Hard-coded Cryptographic Key