PT-2026-6803 · Beyondtrust · Beyondtrust Remote Support+1
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
BeyondTrust Remote Support versions prior to 25.3.2
BeyondTrust Privileged Remote Access versions prior to 25.1.1
Description
BeyondTrust Remote Support and Privileged Remote Access contain a pre-authentication operating system command injection flaw. This issue occurs because the software fails to neutralize special elements used in OS commands, allowing an unauthenticated remote attacker to execute arbitrary code in the context of the site user by sending specially crafted requests. Attackers have been observed extracting portal data and opening WebSocket channels to trigger this remote code execution. Approximately 11,000 instances of these products are exposed to the internet, with around 8,500 being on-premises deployments.
Recommendations
Update BeyondTrust Remote Support to version 25.3.2 or apply the BT26-02-RS patch.
Update BeyondTrust Privileged Remote Access to version 25.1.1 or apply the BT26-02-PRA patch.
Exploit
Fix
RCE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Beyondtrust Remote Support
Privileged Remote Access