Executive Summary
CVE-2026-28326 is a critical unauthenticated remote code execution vulnerability in SolarWinds Access Rights Manager (ARM) that allows attackers to gain NT AUTHORITY\SYSTEM privileges. The flaw stems from a hardcoded authentication key shipped with every installation, enabling attackers who can reach TCP port 55555 to bypass authentication and exploit .NET deserialization vulnerabilities. Given ARM's role in managing identity governance across Active Directory, file servers, and Exchange systems, successful exploitation provides attackers with extensive access to organizational assets. SolarWinds fixed the vulnerability in version 2026.2.1.7 by removing the vulnerable authentication fallback entirely.
This incident highlights the growing threat to identity governance platforms, which have become high-value targets due to their privileged access across enterprise environments. As organizations increasingly adopt zero-trust architectures, securing identity management infrastructure becomes critical to preventing supply chain compromises.
Why This Matters Now
Identity governance platforms like ARM are becoming prime targets for sophisticated threat actors seeking to compromise entire enterprise environments. The hardcoded authentication bypass demonstrates how supply chain vulnerabilities can provide immediate system-level access to critical infrastructure managing organizational permissions.
Attack Path Analysis
Attackers exploited CVE-2026-28326 in SolarWinds Access Rights Manager by leveraging a hardcoded authentication key to achieve unauthenticated remote code execution on TCP port 55555. Once inside the identity governance system running as NT AUTHORITY\SYSTEM, attackers could escalate privileges across Active Directory, move laterally through file servers and Exchange systems using delegated credentials, establish command and control through the compromised ARM infrastructure, exfiltrate sensitive identity and permissions data, and ultimately impact the entire organizational identity fabric by manipulating access rights across all connected systems.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers exploited CVE-2026-28326 using hardcoded static key to bypass gRPC authentication on TCP port 55555, achieving unauthenticated remote code execution as NT AUTHORITY\SYSTEM on SolarWinds ARM server
Related CVEs
CVE-2026-28326
CVSS 8.8An unauthenticated remote code execution vulnerability in SolarWinds Access Rights Manager stemming from a hardcoded static key that allows attackers to bypass authentication and execute arbitrary code with NT AUTHORITY\SYSTEM privileges.
Affected Products:
SolarWinds Access Rights Manager – < 2026.2.1.7
Exploit Status:
proof of concept
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Process Injection: Dynamic-link Library Injection
Exploitation for Privilege Escalation
Valid Accounts: Local Accounts
Obfuscated Files or Information: Command Line Interface
Protocol Tunneling
Server Software Component: Web Shell
Remote Services: Remote Desktop Protocol
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Software Security Frameworks and Practices
Control ID: 6.2.4
NYDFS 23 NYCRR 500 – Penetration Testing and Vulnerability Assessments
Control ID: 500.15
DORA – Identification and Classification of ICT Risk
Control ID: Article 8
CISA ZTMM 2.0 – Identity Governance and Administration
Control ID: Identity Pillar
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
ISO 27001:2022 – Secure Development Policy
Control ID: A.14.2.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
SolarWinds ARM supply-chain vulnerability exposes identity governance systems managing banking credentials, requiring immediate patching and network segmentation to prevent unauthorized access to financial data.
Health Care / Life Sciences
Critical RCE vulnerability in identity management systems threatens HIPAA compliance and patient data security, demanding urgent updates and traffic encryption to protect healthcare infrastructure.
Government Administration
Supply-chain compromise of access rights management creates severe national security risks, exposing government credentials and requiring zero-trust segmentation and enhanced monitoring capabilities.
Information Technology/IT
IT service providers face cascading supply-chain attacks through compromised SolarWinds infrastructure, necessitating multicloud visibility controls and immediate vulnerability detection across client environments.
Sources
- Master Key Included: Detecting SolarWinds ARM CVE-2026-28326https://bishopfox.com/blog/detecting-solarwinds-arm-cve-2026-28326Verified
- SolarWinds Access Rights Manager 2026.2.1 Release Noteshttps://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2026-2-1_release_notes.htmVerified
- CVE-2026-28326 Detection Toolhttps://github.com/BishopFox/CVE-2026-28326-checkVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would be highly relevant to this SolarWinds ARM compromise as it could have constrained the attacker's lateral movement through segmented network access and reduced the blast radius across the identity infrastructure.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Network segmentation policies would likely have limited the attacker's ability to reach the SolarWinds ARM server from untrusted network zones, potentially constraining access to the vulnerable TCP port 55555 service through microsegmentation controls.
Control: Zero Trust Segmentation
Mitigation: Workload-level segmentation would likely have constrained the attacker's ability to leverage ARM's delegated credentials across multiple identity systems, reducing the scope of privilege escalation from the compromised ARM server to connected infrastructure.
Control: East-West Traffic Security
Mitigation: East-west traffic inspection and microsegmentation would likely have limited the attacker's lateral movement pathways between ARM and target systems, constraining their ability to pivot freely through the Active Directory infrastructure using compromised credentials.
Control: Multicloud Visibility & Control
Mitigation: Network visibility and behavioral monitoring would likely have detected anomalous outbound communication patterns from the compromised ARM server, potentially constraining the attacker's ability to maintain persistent command and control channels through legitimate network paths.
Control: Egress Security & Policy Enforcement
Mitigation: Egress filtering and data loss prevention controls would likely have constrained the attacker's ability to exfiltrate large volumes of identity governance data, reducing the scope of sensitive information that could be transmitted to external command and control infrastructure.
While Zero Trust segmentation would likely limit the scope of identity manipulation, attackers could still modify permissions within the directly compromised ARM system, though their ability to propagate changes across the broader identity fabric would be significantly constrained.
Impact at a Glance
Affected Business Functions
- Identity and Access Management
- Active Directory Administration
- File Server Permission Management
- Exchange and SharePoint Access Control
Estimated downtime: 3 days
Estimated loss: N/A
Complete compromise of identity governance system with potential access to all managed file servers, mailboxes, and user accounts across the enterprise. Attacker gains NT AUTHORITY\SYSTEM privileges on ARM servers with delegated administrative rights.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to isolate identity governance systems like ARM from general network access, restricting TCP 55555 to only authorized components through microsegmentation policies
- • Deploy Egress Security & Policy Enforcement to detect and block unauthorized outbound communications from compromised identity management systems, preventing command and control establishment
- • Enable Multicloud Visibility & Control to monitor anomalous interactions with identity governance platforms and detect suspicious automation or repeated malformed requests against critical services
- • Strengthen East-West Traffic Security to prevent lateral movement from compromised identity systems to Active Directory, file servers, and Exchange through workload-to-workload traffic inspection
- • Implement Inline IPS (Suricata) to detect and block known exploit patterns targeting identity management vulnerabilities like CVE-2026-28326 through signature-based detection of malicious payloads



