PT-2026-6803 · Beyondtrust · Beyondtrust Remote Support+1

·

CVE-2026-1731

·

Published

2026-01-31

·

Updated

2026-09-01

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions BeyondTrust Remote Support versions prior to 25.3.2 BeyondTrust Privileged Remote Access versions prior to 25.1.1
Description BeyondTrust Remote Support and Privileged Remote Access contain a pre-authentication operating system command injection flaw. This issue occurs because the software fails to neutralize special elements used in OS commands, allowing an unauthenticated remote attacker to execute arbitrary code in the context of the site user by sending specially crafted requests. Attackers have been observed extracting portal data and opening WebSocket channels to trigger this remote code execution. Approximately 11,000 instances of these products are exposed to the internet, with around 8,500 being on-premises deployments.
Recommendations Update BeyondTrust Remote Support to version 25.3.2 or apply the BT26-02-RS patch. Update BeyondTrust Privileged Remote Access to version 25.1.1 or apply the BT26-02-PRA patch.

Exploit

Fix

RCE

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-03413
CVE-2026-1731

Affected Products

Beyondtrust Remote Support
Privileged Remote Access