• PoC PUBLIC

CVE-2026-28326: pre-auth remote code execution in SolarWinds Access Rights Manager

An unauthenticated attacker can execute arbitrary code against SolarWinds Access Rights Manager by abusing a hardcoded static key, tracked as CVE-2026-28326. The vulnerability affects Access Rights Manager 2026.2 and all previous 2026.x releases listed, and requires only adjacent-network access (no user interaction and no privileges). Successful exploitation can lead to full confidentiality, integrity, and availability loss on affected installs.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
8.8HIGH
EPSS
0.00694
CWE
CWE-321
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Act urgently: public exploit code exists for this flaw, so reduce exposure immediately and implement vendor guidance or network restrictions where possible.

What is CVE-2026-28326?

An unauthenticated attacker can execute arbitrary code against SolarWinds Access Rights Manager by abusing a hardcoded static key, tracked as CVE-2026-28326. The vulnerability affects Access Rights Manager 2026.2 and all previous 2026.x releases listed, and requires only adjacent-network access (no user interaction and no privileges). Successful exploitation can lead to full confidentiality, integrity, and availability loss on affected installs.

Vector CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of SolarWinds Access Rights Manager are affected?

BRANCHAFFECTEDFIXED
2026.x2026.2 and all previous versions

Is CVE-2026-28326 being exploited?

Public exploit code is available.

How to fix CVE-2026-28326

  1. Isolate Access Rights Manager instances from untrusted and adjacent networks and restrict access to trusted management subnets.
  2. Apply network-level controls (firewalls, VLANs) to limit exposure and require management access via VPN or jump hosts.
  3. Monitor logs and alerts for suspicious activity and attempts to use the static key or abnormal authentication behavior.
  4. Follow any vendor guidance from SolarWinds and prepare to deploy vendor-supplied patches when they become available.

Frequently asked questions

Is CVE-2026-28326 being actively exploited?

SolarWinds Access Rights Manager has public exploit code available, but there are no confirmed public reports of active exploitation as of 2026-09-29.

Which Access Rights Manager versions are affected by CVE-2026-28326?

Access Rights Manager 2026.2 and all previous 2026.x versions are listed as affected.

Is there a patch for CVE-2026-28326?

There are no fixed versions listed for this issue; administrators should follow vendor guidance and apply mitigations until a vendor patch is released.

Does CVE-2026-28326 require authentication?

No, CVE-2026-28326 is an unauthenticated vulnerability in SolarWinds Access Rights Manager and does not require valid credentials to exploit.

References