Description
A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support and Privileged Remote Access. Improper validation of authentication data may allow a network-positioned attacker to bypass access controls and gain unauthorized access to the appliance, including accounts with elevated privileges. Exploitation requires a specific authentication configuration to be enabled
Published: 2026-07-06
Score: 9.2 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A pre‑authentication vulnerability in the authentication subsystem of BeyondTrust Remote Support and BeyondTrust Privileged Remote Access allows an attacker to bypass authentication checks before the user is verified. Improper validation of authentication data may enable a network‑positioned attacker to gain unauthorized control of the appliance and to assume accounts with elevated privileges. The weakness is a classical authentication bypass (CWE‑287).

Affected Systems

The flaw affects both BeyondTrust Privileged Remote Access and BeyondTrust Remote Support; the advisory does not list specific product versions, so administrators should review the vendor’s release notes to identify whether their deployed versions contain the fix.

Risk and Exploitability

The CVSS score of 9.2 classifies the vulnerability as critical. The EPSS score is less than 1%, indicating a low probability of exploitation, and the vulnerability is not present in the CISA KEV catalog, meaning no public exploits are known. The attack requires an attacker that can reach the appliance over the network and the presence of a specific authentication configuration that triggers the bypass. Based on the description, it is inferred that the most likely attack vector is a network‑based attempt against the vulnerable authentication service in a setting where the vulnerable configuration is enabled.

Generated by OpenCVE AI on July 26, 2026 at 20:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor patch or update for BeyondTrust Remote Support and Privileged Remote Access, fixes the authentication bypass (CWE‑287).
  • If a patch is not yet available, immediately disable the authentication configuration that triggers the bypass until a fix is applied, thereby mitigating the CWE‑287 vulnerability.
  • Restrict external access to the appliance with firewall rules or network segmentation, limiting attack surface for the authentication bypass issue.
  • Add multi‑factor authentication to the appliance’s login process to increase verification complexity and reduce the impact of any remaining authentication weaknesses (CWE‑287).
  • Continuously monitor authentication logs for anomalous login attempts and configure alerts for repeated failed authentications, enabling early detection of potential exploitation attempts targeting the authentication bypass flaw.

Generated by OpenCVE AI on July 26, 2026 at 20:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 06 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Beyondtrust
Beyondtrust privileged Remote Access
Beyondtrust remote Support
Vendors & Products Beyondtrust
Beyondtrust privileged Remote Access
Beyondtrust remote Support

Mon, 06 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Description A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support and Privileged Remote Access. Improper validation of authentication data may allow a network-positioned attacker to bypass access controls and gain unauthorized access to the appliance, including accounts with elevated privileges. Exploitation requires a specific authentication configuration to be enabled
Title Critical Pre-Authentication Vulnerability in BeyondTrust Remote Support and Privileged Remote Access
Weaknesses CWE-287
References
Metrics cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Beyondtrust Privileged Remote Access Remote Support
cve-icon MITRE

Status: PUBLISHED

Assigner: BT

Published:

Updated: 2026-07-07T14:59:19.946Z

Reserved: 2026-04-09T18:36:13.133Z

Link: CVE-2026-40138

cve-icon Vulnrichment

Updated: 2026-07-06T18:54:36.990Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T20:30:03Z

Weaknesses