SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability. The issue stems from a hardcoded static key.
High CVSS 8.8
Summary
SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability. The issue stems from a hardcoded static key.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://documentation.solarwinds.com/en/success_center/arm/content/secure-your-arm-deployment.htm
- https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/arm_2026-2-1_release_notes.htm
- https://www.solarwinds.com/trust-center/security-advisories/CVE-2026-28326
Timeline
- nvd_ingest NVD