Master Key Included: Detecting SolarWinds ARM CVE-2026-28326
Below is the opening; the full story is at Bishop Fox.
From Bishop Fox
TL;DR
Identity governance software decides who may open which file, mailbox, and account across a company, which makes any one of them a shortcut to all of it. This post is about a flaw that hands that position to anyone who can reach the server.
CVE-2026-28326 is an unauthenticated RCE in SolarWinds Access Rights Manager, fixed in 2026.2.1.7. A client-authentication secret ships with the product, identical on every install, so reaching TCP 55555 is enough to hit a .NET deserialization sink. SolarWinds scored it 8.8 on a vector that assumes adjacent-network reach; check how far your 55555 is exposed. We confirmed execution as
NT AUTHORITY\SYSTEM. Our CVE-2026-28326-check">detection tool determines whether an asset is vulnerable with two safe requests.…
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.