news.mlab.sh
Back to the feed
vulnerability

SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE

CriticalCVSS 9.8
Summary

SolarWinds has released security updates to address a critical vulnerability in its Access Rights Manager (ARM) software, allowing unauthenticated remote code execution. This flaw, discovered by Armadin security researcher Kai Huang, stems from a hard-coded key and has been patched in version 2026.2.1. The vulnerability follows previous fixes for related issues within Web Help Desk and Serv-U, highlighting a sustained effort to address security weaknesses.

SolarWinds has released security updates to address a high-severity vulnerability in its Access Rights Manager (ARM) software. This vulnerability, tracked as CVE-2026-28326, allows an attacker to execute code without authentication, a significant risk given the software's role in managing user permissions. The issue affects all versions of Access Rights Manager 2026.2 and prior.

Armadin security researcher Kai Huang discovered and reported the flaw. SolarWinds credits Huang with identifying the vulnerability and states that it stems from a hard-coded static key. The company released ARM 2026.2.1 as a patch to resolve the issue.

This development follows previous security updates for Web Help Desk (WHD) (CVE-2026-28323, CVSS score: 9.8) which could lead to a SAML authentication bypass when SAML 2.0 authentication is enabled, and another DoS vulnerability (CVE-2026-28299, CVSS score: 8.2) that could cause the Web Help Desk server to crash due to insufficient memory. Both WHD and ARM vulnerabilities have been addressed in version 2026.2.1.

Furthermore, SolarWinds has released fixes for 16 flaws impacting Serv-U (CVE-2026-28302 through CVE-2026-28317, CVE-2026-28321, CVE-2026-28323) that could lead to privilege escalation, remote code execution, and the creation of administrator accounts. These fixes are included in Serv-U version 2026.2.1.

Read the full article at The Hacker News