CVE-2026-28326
CVSS 8.8 HIGH: solarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability. EPSS 0.5% (45º percentile).
Vulnerabilità ed exploit
SolarWinds ha corretto CVE-2026-28326 in Access Rights Manager 2026.2.1. La falla consente una remote code execution senza autenticazione e riguarda tutte le versioni di ARM 2026.2 e precedenti. L’azienda ha attribuito la scoperta a Kai Huang di Armadin e non segnala sfruttamento in the wild.
Il problema nasce da una chiave statica hard-coded. In pratica, il controllo di fiducia non viene creato per singola installazione: se quella chiave viene accettata o recuperata, il prodotto tratta la richiesta come legittima e può arrivare all’esecuzione di codice senza login.
Per chi amministra ARM, il punto non è solo la gravità della CVE. Il segnale è che un controllo interno fissato nel prodotto può abbattere la barriera di accesso anche quando l’ambiente sembra protetto dal perimetro.
1 fonte · 19 set
CVSS 8.8 HIGH: solarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability. EPSS 0.5% (45º percentile).
The Hacker News
SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE
SolarWinds patched an ARM flaw caused by a hard-coded static key that could enable unauthenticated remote code execution.
originalePart of the PlainSec briefing for 2026-09-20
Every edition of this story: SolarWinds corregge un RCE senza login in ARM