Enterprise identity software maintainers have distributed security updates for an identity governance platform to resolve a high-severity security flaw. The vulnerability allows unauthenticated remote network actors to leverage a hard-coded static key to execute arbitrary system commands on management servers.
The vulnerability, tracked as CVE-2026-28326 with a CVSS score of 8.8, impacts SolarWinds Access Rights Manager versions 2026.2 and earlier. The issue stems from the use of a static cryptographic key within communication authentication modules. An unauthenticated remote attacker can construct encrypted network payloads using the known static key to bypass access controls, executing arbitrary code with high privileges under the ARM service account context.
Subverting identity governance and access management tools undermines enterprise Active Directory security boundaries. Because Access Rights Manager processes user provisioning, active directory permission changes, and compliance auditing, an unauthenticated server compromise allows adversaries to create rogue domain administrator accounts and alter user permission structures across the enterprise.
– Force immediate maintenance upgrades across all SolarWinds Access Rights Manager installations to release version 2026.2.1.
– Restrict network access to ARM server ports, permitting connections exclusively from trusted administrative IP pools.
– Inspect ARM service logs and active directory audit trails for unauthorized permission alterations or rogue account creations.
– Rotate service account credentials and encryption certificates associated with Access Rights Manager infrastructure.
Identity governance platform defense demands robust cryptographic key management and prompt patch execution to ensure access control servers remain insulated from unauthenticated remote code execution. #CodeDefence #SolarWinds #AccessRightsManager #RCE #StaticKey #IdentitySecurity #ActiveDirectory #AppSec
/
