PT-2026-55950 · Beyondtrust · Remote Support+1

CVE-2026-40138

·

Published

2026-07-06

·

Updated

2026-08-11

CVSS v4.0

9.2

Critical

VectorAV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions BeyondTrust Remote Support and Privileged Remote Access versions prior to 26.2.1 BeyondTrust Remote Support and Privileged Remote Access versions prior to 25.3.3
Description A critical pre-authentication flaw exists in the authentication subsystem of BeyondTrust Remote Support and Privileged Remote Access. Improper validation of authentication data allows a network-positioned attacker to bypass access controls and gain unauthorized access to the appliance, including accounts with elevated privileges. Exploitation requires a specific authentication configuration to be enabled. Approximately 2,000 instances have been identified as exposed online.
Recommendations Upgrade to version 26.2.1. Upgrade to version 25.3.3. For self-hosted environments, apply the April security rollup.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40138

Affected Products

Privileged Remote Access
Remote Support