CVE-2023-40057: SolarWinds Access Rights Manager
Critical severity, CVSS 9.0. EPSS: 4.9% chance of exploitation in the next 30 days.
The SolarWinds Access Rights Manager was found to be susceptible to a Remote Code Execution Vulnerability. If exploited, this vulnerability allows an authenticated user to abuse a SolarWinds service resulting in remote code execution.
Affected products
- SolarWinds Access Rights Manager: before 2023.2.2 (fixed in 2023.2.2)
Published 2024-02-15. Last modified 2026-06-17.