Description
BeyondTrust Remote Support and Privileged Remote Access contain a high-severity pre-authentication vulnerability in the network communication subsystem. Insufficient validation of client-supplied input may allow an unauthenticated remote attacker to trigger a denial-of-service condition affecting appliance availability.
Published: 2026-07-06
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

BeyondTrust Remote Support and Privileged Remote Access contain a pre‑authentication vulnerability that allows an unauthenticated attacker to send malformed client‑supplied data to the appliance's network communication subsystem. Insufficient validation of that data can trigger a denial‑of‑service condition, rendering the appliance unavailable and disrupting the service for all users that depend on it. The weakness is an input‑validation flaw classified as CWE‑400 and does not provide authentication bypass or data exfiltration capabilities.

Affected Systems

The vulnerability impacts BeyondTrust Remote Support and Privileged Remote Access products. No specific version information is provided, so any current or future releases may be susceptible until the vendor releases a fix.

Risk and Exploitability

The CVSS score of 8.7 indicates a high severity risk, but the EPSS score of less than 1% implies that automated exploitation is presently unlikely. The flaw can be abused over the network by sending crafted packets to the appliance’s communication ports, and it is not listed in the CISA KEV catalog. An attacker would only need unauthenticated network access to the appliance and could disrupt service availability for all users.

Generated by OpenCVE AI on July 23, 2026 at 14:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied patch for BeyondTrust Remote Support and Privileged Remote Access as soon as it becomes available.
  • If a patch is not yet available, implement network‑level filtering or rate limiting on the ports used by the appliance to reduce the likelihood of a successful DoS attack.
  • Monitor appliance logs for abnormal connection attempts or repeated malformed packets and raise alerts if potential DoS activity is detected.

Generated by OpenCVE AI on July 23, 2026 at 14:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 06 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Beyondtrust
Beyondtrust privileged Remote Access
Beyondtrust remote Support
Vendors & Products Beyondtrust
Beyondtrust privileged Remote Access
Beyondtrust remote Support

Mon, 06 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Description BeyondTrust Remote Support and Privileged Remote Access contain a high-severity pre-authentication vulnerability in the network communication subsystem. Insufficient validation of client-supplied input may allow an unauthenticated remote attacker to trigger a denial-of-service condition affecting appliance availability.
Title High-Severity Pre-Authentication Vulnerability in BeyondTrust Remote Support and Privileged Remote Access
Weaknesses CWE-400
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Beyondtrust Privileged Remote Access Remote Support
cve-icon MITRE

Status: PUBLISHED

Assigner: BT

Published:

Updated: 2026-07-07T15:01:24.511Z

Reserved: 2026-04-09T18:36:13.133Z

Link: CVE-2026-40140

cve-icon Vulnrichment

Updated: 2026-07-06T18:55:31.432Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-23T15:00:14Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption