Impact
SolarWinds Access Rights Manager suffers from an unauthenticated remote code execution flaw that arises because the application stores a hardcoded static key. This weakness means that an attacker who can reach the exposed interfaces can run arbitrary commands on the managed host without needing any credentials, potentially allowing full takeover of the system, data exfiltration, and persistence mechanisms. The violation is a cryptographic flaw (CWE-321) that directly undermines confidentiality, integrity, and availability of the affected environment.
Affected Systems
The vulnerability affects all installations of SolarWinds Access Rights Manager that were deployed before the release of version 2026.2.1. The CNA has identified the product name as Access Rights Manager and recommends that users upgrade to the 2026.2.1 release, which eliminates the hardcoded key and presumably fixes the code path that permits the exploit.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.8, indicating a high severity. The EPSS score is reported as less than 1 %, suggesting a low probability of exploitation at present, and it is not listed in CISA’s KEV catalogue. Nevertheless, the attack path is likely to be remote over the network with no authentication required, so any exposed instance of the service could be targeted. Given the high impact and sufficient network exposure, the risk remains significant for organizations that have not applied the vendor’s patch yet.
OpenCVE Enrichment