8.8
CVE-2026-28326
- EPSS 0.55%
- Veröffentlicht 17.09.2026 16:30:31
- Zuletzt bearbeitet 18.09.2026 19:07:38
- Erkennungen
SolarWinds Access Rights Manager Unauthenticated Remote Code Execution Vulnerability
SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability. The issue stems from a hardcoded static key.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerSolarWinds
≫
Produkt
Access Rights Manager
Default Statusunaffected
Version
2026.2 and all previous versions
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.55% | 0.447 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| psirt@solarwinds.com | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-321 Use of Hard-coded Cryptographic Key
The product uses a hard-coded, unchangeable cryptographic key.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://documentation.solarwinds.com/en/success_center/arm/content/secure-your-arm-deployment.htm
https://www.solarwinds.com/trust-center/security-advisories/CVE-2026-28326
https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/arm_2026-2-1_release_notes.htm