BlackTree Security · Infrastructure · Automation · AI

SolarWinds Shipped a Release With No Features, Just an Unauthenticated RCE Fix

SolarWinds Access Rights Manager 2026.2.1 is a release with no new features. That is the point. Its most important change is the removal of a hardcoded static key that could let an unauthenticated attacker execute code remotely.

CVE-2026-28326 is rated 8.8 High by SolarWinds. The vendor’s release notes say the issue stems from a hardcoded static key and was fixed in ARM 2026.2.1, released on 17 September.

The product’s trust position raises the impact

Access Rights Manager is designed to analyse and administer permissions across environments such as Active Directory and file services. An attacker who compromises the management application may gain access to the relationships, credentials and administrative routes organisations use to control privileged access.

The advisory establishes unauthenticated remote code execution. It does not prove that every deployment exposes ARM directly to the internet, or that all connected directories can be controlled through the same exploit. The real blast radius depends on deployment architecture and the authority granted to the ARM services.

No known exploitation does not make the old build acceptable

SolarWinds does not report exploitation in the wild, and the reviewed sources did not establish a public proof of concept. The cause is still a hardcoded secret, a class of weakness that can become much easier to reproduce once researchers compare the fixed and vulnerable code.

Customers upgrading from versions earlier than ARM 2023.2.4 must first move to that intermediate release before installing the current build. That prerequisite should be included in change planning so urgency does not turn into an unsupported upgrade path.

Patch the manager and map what it could reach

  • Upgrade to ARM 2026.2.1. Follow the vendor’s intermediate-version requirement where it applies.
  • Reduce network exposure. Restrict the application and administrative interfaces to trusted systems and users.
  • Inventory connected authority. Record the directories, file systems, mailboxes and service credentials available to ARM.
  • Review the vulnerable period. Check application, Windows, identity and network logs for unexpected access or process execution.
  • Protect recovery evidence. Export relevant logs and configuration before destructive response work.
  • Verify normal operation. Confirm collectors, group updates, alerts and scheduled actions after the upgrade.

The absence of features in this release is useful information. It removes the usual debate about whether an upgrade is worth the disruption. The reason to deploy it is the trust boundary closed by CVE-2026-28326.

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *