Executive brief
BeyondTrust Remote Support and Privileged Remote Access solutions are affected by a critical security flaw in how they verify user identities. A remote attacker could bypass security controls to gain full access to the management appliance, potentially taking over administrative accounts. This could lead to a total compromise of the remote access infrastructure used to manage sensitive corporate systems.
Technical details
A critical improper authentication vulnerability (CWE-287) exists in the authentication subsystem of BeyondTrust Remote Support and Privileged Remote Access. The flaw stems from improper validation of authentication data, which can be exploited by a network-positioned attacker to bypass access controls without prior credentials. Successful exploitation allows for unauthorized access to the appliance, including accounts with elevated privileges. The vulnerability requires a specific, though unspecified, authentication configuration to be enabled. BeyondTrust has released patches in versions 25.3.3 and 26.2.1 to address this issue.
Affected products
- BeyondTrust Remote Support < 25.3.3, < 26.2.1
- BeyondTrust Privileged Remote Access < 25.3.3, < 26.2.1
Timeline
- 2026-07-06: disclosed
- 2026-07-06: advisory