PT-2026-95001 · Solarwinds · Access Rights Manager

·

CVE-2026-28326

·

Published

2026-09-17

·

Updated

2026-10-07

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SolarWinds Access Rights Manager versions prior to 2026.2.1.7
Description An unauthenticated remote code execution issue exists due to a hardcoded shared HMAC secret included in the installer that is identical across all deployments. The gRPC listener on TCP port 55555 allows a fallback authentication path where a caller can bypass authentication by presenting no client certificate and providing an HMAC token computed from the static key. This allows an attacker to reach a BinaryFormatter deserialization sink carrying .NET Remoting traffic, which is protected only by a limited denylist of regex patterns. Successful exploitation allows for command execution as NT AUTHORITYSYSTEM. The vulnerability can be identified by querying the GET /api/armconfig/network/Connections endpoint of the GrantMA service; a record showing IsAuthenticated: false paired with a populated ClientCertThumbPrint indicates the use of the vulnerable fallback path.
Recommendations Update SolarWinds Access Rights Manager to version 2026.2.1.7. Restrict network access to TCP port 55555 to only trusted management hosts via firewall rules or Access Control Lists (ACLs).

Fix

LPE

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-28326

Affected Products

Access Rights Manager