← Back to search

CVE-2026-28326

8.8 HIGH

Published 2026-09-17 · Updated 2026-09-18

AI risk analysis

Summary
The flaw in SolarWinds Access Rights Manager allows unauthenticated attackers to execute remote code due to a hardcoded static key, posing a significant security risk.
Exploitability
Exploitation is relatively straightforward given the unauthenticated nature and the presence of a hardcoded key, making it a high-priority vulnerability to address.
Blast radius
If exploited, the vulnerability could lead to full control of the affected system, potentially compromising sensitive data and operations.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to the latest version of SolarWinds Access Rights Manager, as no specific version is mentioned in the description.
rceunauthwebhardcodedpatch

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability. The issue stems from a hardcoded static key.

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-321

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.