SolarWinds Patched a Hardcoded Key in Access Rights Manager
1SolarWinds Lists Every Version It Shipped as Affected
Companies use SolarWinds Access Rights Manager to check and change who has access to their file servers, Active Directory and SharePoint. Doing that job means holding permission to read and rewrite permissions across all of them. On September 17, 2026, SolarWinds published an advisory for CVE-2026-28326, a flaw rated 8.8 out of 10 and caused by a hardcoded static key, meaning a secret compiled into the product rather than created separately for each install. Products in this category hold standing access across everything they govern, which is what separates a flaw in one of them from a flaw in an ordinary application.
SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability. The issue stems from a hardcoded static key.
SolarWinds security advisory, CVE-2026-28326
SolarWinds scores the flaw for an attacker who is already inside the network, on the same segment or connected through a VPN or an administrative zone, rather than one coming straight off the internet. Past that point it needs no credentials and no action from any user. SolarWinds credits the finding to Kai Huang of Armadin and fixed the flaw in Access Rights Manager 2026.2.1. The advisory does not say whether updating replaces the key on a system that already runs the software or only stops shipping it in new copies.
2An Attacker Inherits the Estate the Software Governs
Access Rights Manager exists to answer who has access to which folders and to change the answer when it is wrong. Running an access review across a Windows estate means holding that permission throughout it. That standing access is the product working as designed. It is also the blast radius of any flaw in it, which is why the shape of the secret matters more than the severity score. Every product in this category holds standing access. What differs is whether the secret protecting it is generated for each customer or compiled into the product. A compiled-in key is one no customer can rotate, which leaves upgrading as the only move available to an operator.
SolarWinds Access Rights Manager 2026.2 and all previous versions
SolarWinds security advisory, affected products
Source: SolarWinds, SolarWinds Access Rights Manager Unauthenticated Remote Code Execution Vulnerability (CVE-2026-28326), September 17, 2026.

