SolarWinds ARM Hard-Coded Key Allows Unauthenticated RCE
CVE-2026-28326 (CVSS 8.8) in SolarWinds Access Rights Manager through 2026.2 lets unauthenticated attackers execute code. Patch ARM 2026.2.1 is available now.

SolarWinds patched CVE-2026-28326 (CVSS 8.8, high) in Access Rights Manager (ARM) on September 17. A static key hard-coded into ARM through version 2026.2 bypasses authentication, letting an unauthenticated attacker execute arbitrary code on the server.
No credentials required. Attack surface: any ARM instance reachable on the network.
SolarWinds states no exploitation in the wild as of the advisory date. Researcher Kai Huang of Armadin reported the flaw.
ARM 2026.2.1 is the fixed build. The SolarWinds security advisory covers affected versions and upgrade paths. SolarWinds notes that restricting network access to the ARM management interface is the workaround where immediate patching is not possible.
Analysis: ARM manages privileged access across enterprise environments. SolarWinds products have drawn sustained attacker interest since the 2020 Sunburst supply chain compromise. No exploitation confirmed now; the risk profile for an unauthenticated RCE in a privileged-access product argues for treating this as high priority.
SolarWinds separately patched critical flaws in Web Help Desk and Serv-U about two months before this disclosure.
For related pre-auth RCE disclosures in IT management software, see N-able’s CVSS 10 flaw in N-central and three JFrog Artifactory flaws exploited for backdoor access. Full CVE details: CVE-2026-28326. More SolarWinds coverage: /topic/solarwinds/.
- [ HIGH ]CVE-2026-28326SolarWinds ARM hard-coded key enables unauthenticated RCE
Found this useful? Share it.