Pre-Authentication Vulnerability in BeyondTrust Remote Support and Privileged Remote Access
CVE-2026-40138
Key Information:
- Vendor
Beyondtrust
- Vendor
- CVE Published:
- 6 July 2026
Badges
What is CVE-2026-40138?
CVE-2026-40138 is a critical pre-authentication vulnerability identified in BeyondTrust's Remote Support and Privileged Remote Access solutions. These products are designed to facilitate secure remote access and support for IT administrators and support personnel. The vulnerability arises from insufficient validation of authentication data within the system's authentication subsystem. This flaw allows an attacker who has network access to exploit the vulnerability and potentially bypass access controls, leading to unauthorized access to the appliance and elevated privilege accounts. The configuration settings required for exploitation necessitate particular attention, as not all setups may be affected equally.
Potential impact of CVE-2026-40138
-
Unauthorized Access: Exploitation of this vulnerability could allow attackers to gain unauthorized access to sensitive systems and data, compromising network integrity and confidentiality.
-
Privilege Escalation: Attackers could leverage this vulnerability to access accounts with elevated privileges, enabling them to manipulate settings, exfiltrate data, or deploy further attacks within the organization’s network.
-
Security Breaches: The presence of this vulnerability significantly raises the risk of security breaches. If exploited, it could lead to extensive data leaks and operational disruptions, resulting in reputational damage and potential compliance issues for organizations.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Privileged Remote Access 0 <= 25.3.2
Remote Support 0 <= 25.3.2
News Articles
BeyondTrust Fixes CVSS 9.2 PAM Bypass in Tools State Hackers Have Targeted for 18 Months
BeyondTrust authentication bypass flaws CVE-2026-40138 and CVE-2026-40139, both CVSS 9.2, let unauthenticated attackers seize administrative control of every system managed by Remote Support and
3 weeks ago
BeyondTrust Patches Authentication Bypass Vulnerabilities | eSecurity Planet
BeyondTrust has patched four RS and PRA vulnerabilities, including two critical authentication bypass flaws.
3 weeks ago
References
CVSS V4
Timeline
- 👾
Exploit known to exist
- 📰
First article discovered by Esecurity Planet
Vulnerability published
Vulnerability Reserved
