Junglewise Threat Intelligence

CVE-2026-40138: BeyondTrust Remote Support and PRA authentication bypass

CVE-2026-40138 · Severity: info · CVSS 9.2 · Published 2026-07-06

Technologies: BeyondTrust Remote Support, BeyondTrust Privileged Remote Access. Vendors: BeyondTrust.

Executive brief

BeyondTrust Remote Support and Privileged Remote Access solutions are affected by a critical security flaw in how they verify user identities. A remote attacker could bypass security controls to gain full access to the management appliance, potentially taking over administrative accounts. This could lead to a total compromise of the remote access infrastructure used to manage sensitive corporate systems.

Technical details

A critical improper authentication vulnerability (CWE-287) exists in the authentication subsystem of BeyondTrust Remote Support and Privileged Remote Access. The flaw stems from improper validation of authentication data, which can be exploited by a network-positioned attacker to bypass access controls without prior credentials. Successful exploitation allows for unauthorized access to the appliance, including accounts with elevated privileges. The vulnerability requires a specific, though unspecified, authentication configuration to be enabled. BeyondTrust has released patches in versions 25.3.3 and 26.2.1 to address this issue.

Affected products

  • BeyondTrust Remote Support < 25.3.3, < 26.2.1
  • BeyondTrust Privileged Remote Access < 25.3.3, < 26.2.1

Timeline

  • 2026-07-06: disclosed
  • 2026-07-06: advisory

References

Related threats