Skip to content

Security1 publisher2 min readPublished

Hard-coded static key in SolarWinds Access Rights Manager hands unauthenticated attackers RCE

CVE-2026-28326 scores 8.8 and affects every build of Access Rights Manager up to 2026.2. The fix is ARM 2026.2.1, and it lands weeks after SolarWinds patched a SAML bypass in Web Help Desk and 16 flaws in Serv-U.

The Watch · Security desk

Illustration accompanying Hard-coded static key in SolarWinds Access Rights Manager hands unauthenticated attackers RCE

What happened

  • Armadin security researcher Kai Huang reported the flaw, and SolarWinds did not report any exploitation in the wild.
  • Nearly two months earlier SolarWinds fixed a 9.8-rated SAML authentication bypass and an 8.2-rated denial-of-service bug in Web Help Desk, both in WHD 2026.2.1.
  • SolarWinds also shipped fixes for 16 Serv-U flaws that could lead to privilege escalation, remote code execution and the creation of administrator accounts.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure A static key is identical in every deployment, so the work of extracting it once from the shipped software applies to every ARM server still running 2026.2 or earlier.
  • decision Teams with one maintenance window should put ARM ahead of Web Help Desk: the ARM defect needs no particular configuration to reach, and the higher-scored WHD bypass needed SAML 2.0 switched on.
  • constraint Anyone signing off Serv-U remediation by CVE number has to go back to SolarWinds to establish which identifier belongs to which product before the list reconciles.
  • cost Three SolarWinds products need attention in the same stretch, so a single estate pays for three separate test-and-deploy cycles inside one release line.

A hard-coded static key is the same secret in every install. Extract it once from the shipped software and it works on the next server, and the one after that. SolarWinds' advisory of September 17, 2026 gives one line of cause: "The issue stems from a hard-coded static key." [4][5] The advisory does not say what the key signs, encrypts or authenticates. [16] Every build of Access Rights Manager up to and including 2026.2 is listed as affected. [2]

The company described the effect in its own words: "SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability." [6] Unauthenticated is the operative word. CVE-2026-28326 scores 8.8 on CVSS. [1] The Web Help Desk SAML authentication bypass SolarWinds fixed nearly two months earlier scored 9.8, and it applied only where the SAML 2.0 authentication method was enabled. [9] The stated condition on the ARM flaw is a version number. [15]

Kai Huang, a security researcher at Armadin, reported the bug and SolarWinds credited him in the advisory. [7] The company did not report exploitation in the wild. [8]

The Serv-U half of the release is harder to audit. SolarWinds says it fixed 16 flaws, then prints the identifiers as CVE-2026-28302, CVE-2026-28304 through CVE-2026-28317, CVE-2026-28321 and CVE-2026-28323. [11] Count them: 1 + 14 + 1 + 1 = 17. [12] CVE-2026-28323 is also the number given for the Web Help Desk SAML bypass, so one identifier sits in two products' fix lists. [13]

Across the three products the common ground is authentication: a static key in ARM, a bypass in Web Help Desk, and privilege escalation plus administrator account creation among the Serv-U fixes. [1][9][11] Two of the fix builds carry the same version string, ARM 2026.2.1 and WHD 2026.2.1. [14]

What to watch

  • Whether a proof of concept for CVE-2026-28326 appears publicly, or SolarWinds updates the advisory to report exploitation.
  • Whether SolarWinds clarifies why CVE-2026-28323 appears in both the Web Help Desk and Serv-U fix lists.
  • Whether upgrading to ARM 2026.2.1 rotates the key on existing installs or only changes the shipped build.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories