Skip to content
SolarWindsCVE-2026-28326

SolarWinds Access Rights Manager: remote code execution

High8.8CVE-2026-28326 · Published Sep 17, 2026 · updated Sep 18, 2026

SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability. The issue stems from a hardcoded static key.

SolarWinds advisory

Affected versions

PackageAffectedFixed in
Access Rights Manager
Product
<= 2026.2 and all previous versionsNo fix yet
Details and references

More SolarWinds advisories

All SolarWinds
Advisory
SolarWinds Observability Self-Hosted: remote code execution
High8.8Sep 22
SolarWinds Observability Self-Hosted: remote code execution
Critical9.8Sep 22
SolarWinds Web Help Desk: authentication bypass
Critical9.8Jul 30
SolarWinds Serv-U: insecure direct object reference
Critical9.1Jul 21
SolarWinds Serv-U: improper access control
Critical9.1Jul 21
SolarWinds Serv-U: privilege escalation
Critical9.1Jul 21

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.