CVE-2024-28074: SolarWinds Access Rights Manager

High severity, CVSS 8.8. EPSS: 10.9% chance of exploitation in the next 30 days.

It was discovered that a previous vulnerability was not completely fixed with SolarWinds Access Rights Manager. While some controls were implemented the researcher was able to bypass these and use a different method to exploit the vulnerability.

Affected products

  • SolarWinds Access Rights Manager: up to and including 2023.2.4

Published 2024-07-17. Last modified 2026-06-17.