Executive brief
SolarWinds Access Rights Manager is an enterprise security tool that manages user access permissions across IT infrastructure. The vulnerability allows attackers to remotely execute arbitrary code on systems without requiring authentication, due to the use of a hardcoded cryptographic key. This could allow attackers to gain complete control over managed systems and compromise the security of the entire organization's access control framework.
Technical details
The vulnerability is a remote code execution flaw caused by a hardcoded static cryptographic key in SolarWinds Access Rights Manager. An attacker can use this known key to bypass authentication and inject malicious code into the application, achieving unauthenticated remote code execution. The attack is network-reachable and requires no user interaction or prior authentication. A successful exploit grants an attacker arbitrary code execution in the context of the application, potentially leading to full system compromise and lateral movement throughout the managed infrastructure.
Affected products
- SolarWinds Access Rights Manager
Timeline
- 2026-09-17: disclosed