Junglewise Threat Intelligence

CVE-2026-40141: BeyondTrust Remote Support and PRA improper input validation

CVE-2026-40141 · Severity: info · CVSS 8.5 · Published 2026-07-06

Technologies: BeyondTrust Remote Support, BeyondTrust Privileged Remote Access. Vendors: BeyondTrust.

Executive brief

BeyondTrust Remote Support and Privileged Remote Access are tools used by organizations to manage secure remote connections and administrative access. A security flaw in these products could allow a user who already has a low-level account to access sensitive data or resources they are not authorized to see. This could lead to the exposure of internal configuration data or unauthorized access to managed systems, though the attacker must already have specific permissions to exploit the bug.

Technical details

A vulnerability classified as Improper Neutralization of Special Elements in Data Query Logic (CWE-943) exists in the web application component of BeyondTrust Remote Support and Privileged Remote Access. The flaw stems from insufficient validation of user-supplied input parameters during data processing. An authenticated attacker with low-level privileges and specific permissions can exploit this to bypass authorization controls and access unintended resources or data. The vulnerability is reachable over the network without user interaction. BeyondTrust has released patches in versions 25.3.3 and 26.2.1 to address this issue.

Affected products

  • BeyondTrust Remote Support < 25.3.3, < 26.2.1
  • BeyondTrust Privileged Remote Access < 25.3.3, < 26.2.1

Timeline

  • 2026-07-06: advisory
  • 2026-07-06: disclosed

References

Related threats