CVE-2026-40141Patch(beyondtrust / privileged_remote_access)

LOWCVSS 9.9 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch beyondtrust privileged_remote_access systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote Access related to the processing of certain input parameters. Insufficient validation of user-supplied input may allow an authenticated attacker with limited privileges to access unintended resources or data beyond their authorization scope. Exploitation is restricted to accounts with specific permissions.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-943

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • privileged_remote_access
  • remote_support

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 5 signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-07-07); latest day: 2
  • 5 total mentions across 3 days

Affected systems

Products
privileged_remote_accessremote_support

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-07-07: 2Mentions · 2026-07-08: 1Mentions · 2026-07-09: 2Patch / Workaround · 2026-07-07: 1Patch / Workaround · 2026-07-08: 1Patch / Workaround · 2026-07-09: 2Technical Details · 2026-07-07: 2Technical Details · 2026-07-08: 1Technical Details · 2026-07-09: 207-0707-0807-09
Signal classification2 categories
Patch
480.0%
Disclosure
120.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-07-072
Disclosure1Patch1
2026-07-081
Patch1
2026-07-092
Patch2
Full discourse5 posts
  • GovCERT.CZ@GOVCERT_CZ
    Patch

    🚨 Upozorňujeme na zranitelnosti v BeyondTrust Remote Support a Privileged Remote Access. V produktech RS a PRA byly identifikovány pre-autentizační chyby v autentizačním subsystému (CVE-2026-40138, CVE-2026-40139) způsobené nedostatečnou validací autentizačních dat a požadavků, které mohou umožnit neautentizovanému útočníkovi v síti obejít přístupové kontroly a získat neoprávněný přístup k zařízení včetně účtů s vyššími oprávněními; zneužitelnost těchto dvou chyb je podmíněna specifickou konfigurací autentizace. Zranitelnost CVE-2026-40140 vyplývá z nedostatečné validace vstupu od klienta a může vést k vyvolání stavu DoS, čímž může být ovlivněna dostupnost systému. Zranitelnost CVE-2026-40141 v komponentě webové aplikace způsobená nedostatečnou validací vstupů může autorizovanému útočníkovi s omezenými právy umožnit přístup k neautorizovaným zdrojům nebo datům; její zneužití je omezeno na účty se specifickými oprávněními. Celkově mohou chyby vést k obcházení autentizace, eskalaci přístupů, narušení integrity systému i dostupnosti služby. 📌Doporučujeme aktualizovat na Remote Support RS 25.3.3 a vyšší a Privileged Remote Access PRA 25.3.3 a vyšší.

    Post summary

    The notice reports several CVE-2026-x vulnerabilities in BeyondTrust services, describes their technical nature, and urges users to apply specific patches (RS 25.3.3+/PRA 25.3.3+).

    040711.1K
    4.3K followersView on X
  • にゃん☆たく/takumi.a@taku888infinity
    Disclosure

    Critical BeyondTrust Authentication Flaws Expose Remote Support Appliances to Attacks https://gbhackers.com/critical-beyondtrust-authentication-flaws/ 『(直訳) CVE-2026-40138 – 重大度:クリティカル(CVSS 9.2):RSおよびPRAにおける不適切な認証(CWE-287)により、認証されていない攻撃者が特定の構成下でアクセス制御を回避し、昇格されたアクセス権を取得できる可能性があります。 CVE-2026-40139 – 重大度:CVSS 9.2:リモートサポートにおける認証処理の欠陥(CWE-287)により、リモート攻撃者が認証を回避して特権アカウントにアクセスできる可能性があります。 CVE-2026-40140 – 高(CVSS 8.7):制御不能なリソース消費(CWE-400)により、認証されていない攻撃者がサービス拒否状態を引き起こし、アプライアンスの可用性に影響を与える可能性があります。 CVE-2026-40141 – 高(CVSS 8.5):不適切な入力無効化(CWE-943)により、認証済みの権限の低いユーザーが不正なデータやリソースにアクセスできる可能性があります。』

    Post summary

    The passage reports on newly disclosed BeyondTrust authentication flaws, providing severity metrics and technical details, but does not share PoC code, exploits, or evidence of active use.

    000431.4K
    11.8K followersView on X
  • Clone Systems@CloneSystemsInc
    Patch

    BeyondTrust has released security updates for multiple vulnerabilities affecting Remote Support and Privileged Remote Access products. The flaws include CVE-2026-40138, CVE-2026-40139, CVE-2026-40140, and CVE-2026-40141, with severity scores reaching as high as 9.9. Successful exploitation could allow attackers to bypass access controls, gain unauthorized access, trigger denial of service conditions, or access resources and data beyond their authorized scope. For organizations using remote support or privileged access tools, this is not a patch to delay. These systems often sit close to sensitive administrative workflows, which makes them high value targets when vulnerabilities are left open. Affected users should update BeyondTrust Remote Support and BeyondTrust Privileged Remote Access to version 25.3.3 or later immediately. Privileged access tools are supposed to protect the keys to the kingdom. Make sure the lock itself is not the weak point. #BeyondTrust #PrivilegedAccessManagement #RemoteSupport #CVE202640138 #CVE202640139 #CVE202640140 #CVE202640141 #VulnerabilityManagement #PatchManagement #CyberRisk

    Post summary

    BeyondTrust released patches for four critical CVEs affecting Remote Support and Privileged Remote Access products, urging users to update immediately.

    0002061
    259 followersView on X
  • 中島佑允(YusukeNakajima)@nakajimeeee
    Patch

    【脆弱性管理】BeyondTrustのリモートアクセス製品に認証バイパスの重大欠陥4件——過去に実被害があった製品ラインに再び高深刻度CVE BeyondTrustは、Remote Support(RS)およびPrivileged Remote Access(PRA)に存在する4件の脆弱性を修正したセキュリティアドバイザリを公開した。うち2件が認証前に悪用可能な重大欠陥であり、特定の認証設定が有効な環境では未認証の攻撃者が管理者権限を含むアカウントへ不正アクセス可能となる。 CVE-2026-40138(CVSS 9.2)はRS・PRA双方の認証サブシステムにおける認証データ検証不備、CVE-2026-40139(CVSS 9.2)はRSの認証リクエスト処理不備で、いずれも特定の認証設定が前提条件となる。CVE-2026-40140(CVSS 8.7)はネットワーク通信サブシステムへの入力検証不備によるDoS、CVE-2026-40141(CVSS 8.5)はRS・PRAのWebアプリコンポーネントにおける限定権限アカウントによる認可範囲外アクセスだ。BeyondTrustによれば、これらはClaude Opus 4.8を含むAIモデルと自社研究ツールを活用した内部セキュリティ評価で発見された。現時点で野外での悪用は確認されていない。 ただし、同製品ラインにおけるCVE-2024-12356およびCVE-2026-1731は過去にWebシェル・バックドア展開に実際に悪用されており、攻撃者の高い関心を受け続ける製品であることを踏まえれば、RS 25.3.3・PRA 25.3.3への早急なアップデートが求められる。 https://thehackernews.com/2026/07/beyondtrust-patches-critical-auth.html

    Post summary

    The advisory announces patches for four critical authentication bypass vulnerabilities in BeyondTrust's Remote Support and Privileged Remote Access products, detailing CVSS scores and attack vectors, and urging immediate updates; no active exploitation has been reported.

    00020517
    3.0K followersView on X
  • Meridian Group@MeridianEU
    Patch

    #BeyondTrust patches four vulnerabilities in Remote Support and PRA: CVE-2026-40138 and CVE-2026-40139 (CVSS 9.2) enable unauthenticated auth bypass including privileged account access. CVE-2026-40140 enables pre-auth DoS; CVE-2026-40141 authenticated authz bypass. #patchrelease https://t.co/v1UUkcsaJ3

    Post summary

    BeyondTrust announces patches for four high‑severity CVEs in Remote Support and PRA, specifying vulnerability types and CVSS scores while directing users to a patch release link.

    0000057
    66 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appbeyondtrustprivileged_remote_access---
Appbeyondtrustremote_support---

Explore more