Pre-Authentication Vulnerability in BeyondTrust Remote Support and Privileged Remote Access
CVE-2026-40138

9.2CRITICAL

Key Information:

Vendor
CVE Published:
6 July 2026

Badges

📈 Score: 1,080👾 Exploit Exists📰 News Worthy

What is CVE-2026-40138?

CVE-2026-40138 is a critical pre-authentication vulnerability identified in BeyondTrust's Remote Support and Privileged Remote Access solutions. These products are designed to facilitate secure remote access and support for IT administrators and support personnel. The vulnerability arises from insufficient validation of authentication data within the system's authentication subsystem. This flaw allows an attacker who has network access to exploit the vulnerability and potentially bypass access controls, leading to unauthorized access to the appliance and elevated privilege accounts. The configuration settings required for exploitation necessitate particular attention, as not all setups may be affected equally.

Potential impact of CVE-2026-40138

  1. Unauthorized Access: Exploitation of this vulnerability could allow attackers to gain unauthorized access to sensitive systems and data, compromising network integrity and confidentiality.

  2. Privilege Escalation: Attackers could leverage this vulnerability to access accounts with elevated privileges, enabling them to manipulate settings, exfiltrate data, or deploy further attacks within the organization’s network.

  3. Security Breaches: The presence of this vulnerability significantly raises the risk of security breaches. If exploited, it could lead to extensive data leaks and operational disruptions, resulting in reputational damage and potential compliance issues for organizations.

Affected Version(s)

Privileged Remote Access 0 <= 25.3.2

Remote Support 0 <= 25.3.2

News Articles

BeyondTrust Fixes CVSS 9.2 PAM Bypass in Tools State Hackers Have Targeted for 18 Months

BeyondTrust authentication bypass flaws CVE-2026-40138 and CVE-2026-40139, both CVSS 9.2, let unauthenticated attackers seize administrative control of every system managed by Remote Support and

3 weeks ago

BeyondTrust Patches Authentication Bypass Vulnerabilities  | eSecurity Planet

BeyondTrust has patched four RS and PRA vulnerabilities, including two critical authentication bypass flaws.

3 weeks ago

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • 👾

    Exploit known to exist

  • 📰

    First article discovered by Esecurity Planet

  • Vulnerability published

  • Vulnerability Reserved

.