SolarWinds has released a patch for a critical vulnerability in its Access Rights Manager (ARM) software. The flaw, designated CVE-2026-28299, enables unauthenticated remote code execution. This issue stems from the presence of a hard-coded static key within the software. All versions of ARM preceding 2026.2.1 are affected by this vulnerability.
The technical mechanism behind this vulnerability involves a hard-coded static key. In software development, hard-coded keys are often used for various internal functions, such as encryption, authentication, or session management. When such a key is static and discoverable, an attacker can potentially leverage it to bypass security controls. In this specific instance, the presence of a hard-coded static key allows an attacker to achieve unauthenticated remote code execution, meaning they can run arbitrary commands on the affected system without needing to provide valid credentials.
The affected product is SolarWinds Access Rights Manager (ARM). ARM is designed to help organizations manage and audit user access rights across their IT infrastructure, providing visibility into who has access to what resources. Given its role in access management, a remote code execution vulnerability in ARM could have significant implications for an organization's security posture.
The scope of this vulnerability encompasses all versions of SolarWinds ARM prior to version 2026.2.1. Organizations utilizing any older iteration of the software are advised to update their installations promptly. Remote code execution flaws are generally considered among the most severe, as they can lead to full system compromise, data exfiltration, or the deployment of further malicious payloads.
Typical mitigation guidance for vulnerabilities of this class involves applying vendor-supplied patches as soon as they become available. Organizations should also ensure that their network segmentation practices limit exposure of management interfaces, such as those for ARM, to untrusted networks. Regular security audits and penetration testing can help identify similar weaknesses before they are exploited.
This patch for ARM follows other recent security advisories from SolarWinds. The company has also addressed significant vulnerabilities in its Web Help Desk and Serv-U products. This series of patches underscores the ongoing challenge for software vendors to identify and remediate critical security flaws, particularly in products that manage core IT infrastructure components.






