CVE-2026-40138
BeyondTrust Remote Support, Privileged Remote Access, privileged remote access
A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support and Privileged Remote Access. Improper validation of authentication data may allow a network-positioned attacker to bypass access controls and gain unauthorized access to the appliance, including accounts with elevated privileges. Exploitation requires a specific authentication configuration to be enabled
- CVSS
- 9.2
- EPSS
- 0.44% 36.3% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.07