Description
A high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote Access related to the processing of certain input parameters. Insufficient validation of user-supplied input may allow an authenticated attacker with limited privileges to access unintended resources or data beyond their authorization scope. Exploitation is restricted to accounts with specific permissions.
Published: 2026-07-06
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A high‑severity flaw exists in a web application component of BeyondTrust Remote Support and Privileged Remote Access. The vulnerability arises from insufficient validation of user‑supplied input parameters, enabling an authenticated attacker with limited privileges to access resources or data beyond their authorized scope. The flaw is classified as CWE‑943, indicating that should be protected.

Affected Systems

BeyondTrust’s Privilege Remote Access and Remote Support products are affected. The advisory does not specify particular releases, so any deployment of these products may be at risk unless the vendor confirms otherwise.

Risk and Exploitability

The CVSS score of 8.5 denotes high severity, yet the EPSS score of < 1% suggests a low probability of exploitation at present. The vulnerability is not listed in CISA’s requires an authenticated account with certain permissions, the likely attack vector is internal or involves compromised credentials; if exploited, the attacker could read or manipulate privileged resources, compromising confidentiality and integrity.

Generated by OpenCVE AI on July 26, 2026 at 20:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest BeyondTrust patch that addresses the input‑validation flaw in the web component.
  • Review all user accounts and restrict permissions so that only necessary privileged roles retain access to the affected features.
  • Enable and monitor strict access controls and audit logging for all privileged operations to detect and deter misuse.

Generated by OpenCVE AI on July 26, 2026 at 20:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 06 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Beyondtrust
Beyondtrust privileged Remote Access
Beyondtrust remote Support
Vendors & Products Beyondtrust
Beyondtrust privileged Remote Access
Beyondtrust remote Support

Mon, 06 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Description A high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote Access related to the processing of certain input parameters. Insufficient validation of user-supplied input may allow an authenticated attacker with limited privileges to access unintended resources or data beyond their authorization scope. Exploitation is restricted to accounts with specific permissions.
Title High-Severity Vulnerability In Web Application Component of BeyondTrust Remote Support and Privileged Remote Access
Weaknesses CWE-943
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H'}


Subscriptions

Beyondtrust Privileged Remote Access Remote Support
cve-icon MITRE

Status: PUBLISHED

Assigner: BT

Published:

Updated: 2026-07-07T14:56:42.895Z

Reserved: 2026-04-09T18:36:13.133Z

Link: CVE-2026-40141

cve-icon Vulnrichment

Updated: 2026-07-06T18:56:08.004Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T20:30:03Z

Weaknesses
  • CWE-943

    Improper Neutralization of Special Elements in Data Query Logic