Executive brief
BeyondTrust Remote Support and Privileged Remote Access are tools used by IT teams to securely manage and troubleshoot remote computers. A critical security flaw in the login system allows an unauthorized person to bypass security checks and gain full access to the management console, potentially taking over administrator accounts. This could lead to a complete compromise of the systems being managed and the exposure of sensitive corporate data.
Technical details
A critical improper authentication vulnerability (CWE-287) exists in the authentication subsystem of BeyondTrust Remote Support and Privileged Remote Access. The flaw stems from improper processing of authentication requests, which can be exploited by a remote, unauthenticated attacker to bypass access controls. Successful exploitation allows the attacker to gain unauthorized access to the appliance, including accounts with elevated privileges. This vulnerability is exploitable only when a specific authentication configuration is enabled. BeyondTrust has released patches in versions 25.3.3 and 26.2.1 to address this issue.
Affected products
- BeyondTrust Remote Support < 25.3.3, < 26.2.1
- BeyondTrust Privileged Remote Access < 25.3.3, < 26.2.1
Timeline
- 2026-07-06: disclosed
- 2026-07-06: advisory