{"id":"CVE-2026-28326","published":"2026-09-17T17:16:39.960","lastModified":"2026-09-18T19:07:38.320","description":"SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability. The issue stems from a hardcoded static key.","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-321"],"vendors":[],"products":[],"references":[{"url":"https://documentation.solarwinds.com/en/success_center/arm/content/secure-your-arm-deployment.htm","tags":[]},{"url":"https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/arm_2026-2-1_release_notes.htm","tags":[]},{"url":"https://www.solarwinds.com/trust-center/security-advisories/CVE-2026-28326","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw in SolarWinds Access Rights Manager allows unauthenticated attackers to execute remote code due to a hardcoded static key, posing a significant security risk.","exploitability":"Exploitation is relatively straightforward given the unauthenticated nature and the presence of a hardcoded key, making it a high-priority vulnerability to address.","blast_radius":"If exploited, the vulnerability could lead to full control of the affected system, potentially compromising sensitive data and operations.","remediation":"Upgrade to the latest version of SolarWinds Access Rights Manager, as no specific version is mentioned in the description.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","unauth","web","hardcoded","patch"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-29T09:26:10.370Z"}}