PT-2026-55950 · Beyondtrust · Remote Support+1
CVE-2026-40138
·
Published
2026-07-06
·
Updated
2026-08-11
CVSS v4.0
9.2
Critical
| Vector | AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
BeyondTrust Remote Support and Privileged Remote Access versions prior to 26.2.1
BeyondTrust Remote Support and Privileged Remote Access versions prior to 25.3.3
Description
A critical pre-authentication flaw exists in the authentication subsystem of BeyondTrust Remote Support and Privileged Remote Access. Improper validation of authentication data allows a network-positioned attacker to bypass access controls and gain unauthorized access to the appliance, including accounts with elevated privileges. Exploitation requires a specific authentication configuration to be enabled. Approximately 2,000 instances have been identified as exposed online.
Recommendations
Upgrade to version 26.2.1.
Upgrade to version 25.3.3.
For self-hosted environments, apply the April security rollup.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Privileged Remote Access
Remote Support