Junglewise Threat Intelligence

CVE-2026-1731: BeyondTrust Remote Support and PRA OS command injection

CVE-2026-1731 · Severity: critical · CVSS 9.9 · Exploited in the wild · Published 2026-02-13

Technologies: BeyondTrust Remote Support (RS), BeyondTrust Privileged Remote Access (PRA), BeyondTrust Remote Support, BeyondTrust Privileged Remote Access. Vendors: BeyondTrust.

Executive brief

BeyondTrust Remote Support and Privileged Remote Access solutions, which are used by organizations to provide secure remote technical support and manage administrative access, are affected by a critical security flaw. An unauthenticated attacker can remotely execute commands on the system, potentially leading to full system takeover, data theft, or service disruption. This vulnerability is reportedly being exploited in the wild, making immediate patching essential to protect corporate infrastructure.

Technical details

A critical OS command injection vulnerability (CWE-78) exists in BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA). The flaw allows an unauthenticated remote attacker to execute arbitrary operating system commands in the context of the site user by sending specially crafted network requests. No user interaction or prior authentication is required for successful exploitation. The vulnerability has been observed in active exploitation. Patches are available in Remote Support version 25.3.2 and Privileged Remote Access version 25.1.

Affected products

  • BeyondTrust Remote Support (RS) versions up to (excluding) 25.3.2
  • BeyondTrust Privileged Remote Access (PRA) versions up to (excluding) 25.1

Timeline

  • 2026-02-06: disclosed: Initial CVE entry received from BeyondTrust
  • 2026-02-13: advisory: Vendor advisory and CISA KEV entry published
  • 2026-02-13: kev added: Added to CISA Known Exploited Vulnerabilities catalog
  • 2026-02-13: exploited: Confirmed active exploitation in the wild

Related threats