CVE-2025-1094General

LOWCVSS 8.1 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Improper neutralization of quoting syntax in PostgreSQL libpq functions PQescapeLiteral(), PQescapeIdentifier(), PQescapeString(), and PQescapeStringConn() allows a database input provider to achieve SQL injection in certain usage patterns. Specifically, SQL injection requires the application to use the function result to construct input to psql, the PostgreSQL interactive terminal. Similarly, improper neutralization of quoting syntax in PostgreSQL command line utility programs allows a source of command line arguments to achieve SQL injection when client_encoding is BIG5 and server_encoding is one of EUC_TW or MULE_INTERNAL. Versions before PostgreSQL 17.3, 16.7, 15.11, 14.16, and 13.19 are affected.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-149

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Threat summary

  • Public PoC is present in monitored signal
  • 1 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-14: 1PoC Mentioned / Linked · 2026-02-14: 1Technical Details · 2026-02-14: 102-14
Signal classification1 categories
General
1100.0%
Referenced assets4 URLs
Full discourse1 post
  • RST Cloud@rst_cloud
    General

    #threatreport #LowCompleteness Reconnaissance Has Begun for the New BeyondTrust RCE (CVE-2026-1731): Here's What We See So Far | 12-02-2025 Source: https://www.greynoise.io/blog/reconnaissance-beyondtrust-rce-cve-2026-1731 Key details below ↓ 🧑‍💻Actors/Campaigns: Hafnium 💀Threats: Beyondtrust_tool, Log4shell_vuln, Simplehelp_tool, 🎯Victims: Beyondtrust customers, Enterprise networks 🏭Industry: Government, Iot 🌐Geo: Polish, Chinese 🔓CVEs: CVE-2025-1094 \[[Vulners](https://vulners.com/cve/CVE-2025-1094)] - CVSS V3.1: *8.1*, - Vulners: Exploitation: True CVE-2026-1731 \[[Vulners](https://vulners.com/cve/CVE-2026-1731)] - CVSS V3.1: *9.9*, - Vulners: Exploitation: Unknown CVE-2024-12356 \[[Vulners](https://vulners.com/cve/CVE-2024-12356)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - beyondtrust privileged_remote_access (le24.3.1) - beyondtrust remote_support (le24.3.1) 🤖LLM extracted TTPs:` T1046, T1078, T1090, T1110, T1190, T1590, T1595, T1595.001 🧨IOCs: - IP: 1 💽Software: Slack, Linux, MOVEit, PostgreSQL #threatreport: CVE-2026-1731 represents a significant security vulnerability in BeyondTrust Remote Support and Privileged Remote Access servers, characterized as an OS command injection flaw with a high severity score of 9.9 (CVSS v4). The vulnerability allows unauthenticated attackers to execute arbitrary commands without requiring user interaction, making it particularly easy to exploit due to its low complexity. Recent reconnaissance activities indicate that a single IP address associated with a commercial VPN service has been responsible for approximately 86% of these probing sessions. This identified actor has been active since 2023 and has rapidly incorporated checks for CVE-2026-1731 into its operational toolkit. Interestingly, the reconnaissance is primarily focused on non-standard ports rather than the default port 443, which suggests that the threat actors are aware that many organizations configure BeyondTrust deployments to use alternative ports as a security measure. Technical analysis of the scanning sessions has uncovered JA4+ fingerprints that indicate the use of shared tooling, leveraging VPN tunneling evidenced by distinct network characteristics. The majority of sessions display a Linux stack at the TCP layer, with one dominant scanner reporting a maximum segment size (MSS) of 1358—indicative of VPN encapsulation. Furthermore, the observed HTTP traffic utilizes two different exploit tools: a lightweight version and a more complex variant, neither of which correlate with known applications in existing databases. Additionally, the actors behind these reconnaissance efforts are not exclusively targeting BeyondTrust. Their activity profile suggests they are simultaneously probing for vulnerabilities in a range of other products, including SonicWall, MOVEit Transfer, Log4j, and Sophos firewalls, alongside conducting brute force attacks on SSH and testing for default credentials in IoT devices. Some of these actors employ out-of-band callback techniques to verify vulnerabilities before executing payloads. The involvement of BeyondTrust's remote access tools in managing privileged network access highlights the critical nature of this vulnerability. Successful exploitation could grant attackers substantial access to enterprise networks. The emergence of CVE-2026-1731 follows a recognizable trend: once disclosed, proof of concept (PoC) exploits are quickly developed, leading to swift reconnaissance actions aimed at identifying vulnerable systems. Such patterns have previously resulted in successful breaches, underscoring the urgency for rapid mitigation efforts in the face of this vulnerability.

    Post summary

    The report highlights that reconnaissance for the high‑severity OS command injection CVE‑2026‑1731 has begun, with PoC likely developed, but no active exploitation or patch information has yet been confirmed.

    00000114
    583 followersView on X

Explore more