SolarWinds ARM hard-coded key enables unauthenticated RCE
Hard-coded static key in SolarWinds Access Rights Manager through 2026.2 lets unauthenticated attackers execute arbitrary code remotely. Fixed in ARM 2026.2.1.
- Vendor
- SolarWinds
- Product
- Access Rights Manager (ARM)
- CVSS
- 8.8
- EPSS (exploit probability)
- 0.5%
- Status
- patched
- Published
A static key hard-coded into SolarWinds Access Rights Manager (ARM) through version 2026.2 lets an unauthenticated attacker bypass authentication and execute arbitrary code on the server. No credentials required to trigger the flaw.
Fixed in ARM 2026.2.1, released September 17, 2026. SolarWinds reports no evidence of exploitation in the wild as of the advisory date. Researcher Kai Huang of Armadin reported the vulnerability.
Upgrade to ARM 2026.2.1. Full version details and upgrade steps are in the SolarWinds advisory. If patching is not immediately possible, restrict network access to the ARM management interface to trusted hosts.
