Skip to content
feed: live
>_0dayNews
← All vendors
Vendor

BeyondTrust

Vulnerabilities and patches across BeyondTrust's remote-access and privileged-access product line — Remote Support (RS), Privileged Remote Access (PRA), and adjacent PAM appliances whose compromise typically hands attackers a foothold in the vendor-and-third-party access path into an enterprise.

7 CVEs1 articlesRSS
CVEs
CVE-2026-40138
[ HIGH ]CVSS 8.1EPSS 0.4%patched

BeyondTrust Remote Support / PRA pre-auth authentication bypass

A pre-authentication authentication-bypass flaw in BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA). Improper validation of authentication data may let a network-positioned attacker bypass access controls and reach appliance accounts, including elevated ones. Vendor labels the flaw "critical" in its advisory; NVD scores it CVSS 8.1 (high). Patched in the 2026-07-06 coordinated release; exploitation requires a specific authentication configuration to be enabled.

BeyondTrust / Remote Support (RS) and Privileged Remote Access (PRA)
CVE-2026-40139
[ CRITICAL ]CVSS 9.8EPSS 0.7%patched

BeyondTrust Remote Support pre-auth authentication bypass (critical)

A critical (CVSS 9.8) pre-authentication authentication-bypass flaw in BeyondTrust Remote Support (RS). Improper processing of authentication requests may let an unauthenticated remote attacker bypass access controls and reach appliance accounts, including elevated ones. Patched in the 2026-07-06 coordinated release; exploitation requires a specific authentication configuration to be enabled.

BeyondTrust / Remote Support (RS)
CVE-2026-40140
[ HIGH ]CVSS 7.5EPSS 0.6%patched

BeyondTrust Remote Support / PRA pre-auth denial of service

A high-severity (CVSS 7.5) pre-authentication denial-of-service flaw in BeyondTrust Remote Support and Privileged Remote Access. Insufficient validation of client-supplied input in the network communication subsystem may let an unauthenticated remote attacker trigger a DoS condition against appliance availability. Patched in the 2026-07-06 coordinated release.

BeyondTrust / Remote Support (RS) and Privileged Remote Access (PRA)
CVE-2026-40141
[ CRITICAL ]CVSS 9.9EPSS 0.5%patched

BeyondTrust Remote Support / PRA authenticated authorization bypass

A critical (CVSS 9.9) authenticated authorization-bypass flaw in a web-application component of BeyondTrust Remote Support and Privileged Remote Access. Insufficient input validation may let an authenticated attacker with limited privileges reach data or resources beyond their authorization scope. Exploitation is restricted to accounts with specific permissions. Patched in the 2026-07-06 coordinated release.

BeyondTrust / Remote Support (RS) and Privileged Remote Access (PRA)
CVE-2026-1731
[ CRITICAL ]CVSS 9.8EPSS 88.6%kev

BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Vulnerability

BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)contain an OS command injection vulnerability. Successful exploitation could allow an unauthenticated remote attacker to execute operating system commands in the context of the site user. Successful exploitation requires no authentication or user interaction and may lead to system compromise, including unauthorized access, data exfiltration, and service disruption.

BeyondTrust / Remote Support (RS) and Privileged Remote Access (PRA)
CVE-2024-12686
[ MEDIUM ]CVSS 6.6EPSS 13.7%kev

BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) OS Command Injection Vulnerability

BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain an OS command injection vulnerability that can be exploited by an attacker with existing administrative privileges to upload a malicious file. Successful exploitation of this vulnerability can allow a remote attacker to execute underlying operating system commands within the context of the site user.

BeyondTrust / Privileged Remote Access (PRA) and Remote Support (RS)
CVE-2024-12356
[ CRITICAL ]CVSS 9.8EPSS 88.0%kev

BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) Command Injection Vulnerability

BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain a command injection vulnerability, which can allow an unauthenticated attacker to inject commands that are run as a site user.

BeyondTrust / Privileged Remote Access (PRA) and Remote Support (RS)
Articles