Executive brief
BeyondTrust Remote Support and Privileged Remote Access appliances are affected by a security flaw that allows an attacker to crash the system remotely. These products are used by organizations to provide secure remote access to employees and support staff. An exploit could result in a total service outage, preventing authorized users from accessing critical systems and disrupting business operations.
Technical details
A denial-of-service (DoS) vulnerability exists in the network communication subsystem of BeyondTrust Remote Support and Privileged Remote Access. The flaw is categorized as CWE-400 (Uncontrolled Resource Consumption) and stems from insufficient validation of client-supplied input. An unauthenticated remote attacker can exploit this by sending specially crafted network traffic to the appliance, leading to resource exhaustion or service failure. This vulnerability is pre-authentication, meaning no valid credentials are required to trigger the crash. Patches are available in versions 25.3.3 and 26.2.1.
Affected products
- BeyondTrust Remote Support < 25.3.3, < 26.2.1
- BeyondTrust Privileged Remote Access < 25.3.3, < 26.2.1
Timeline
- 2026-07-06: disclosed
- 2026-07-06: advisory