← Vulnerability feed

Vulnerability record · CVE-2026-1731 · published 6 February 2026

CVE-2026-1731: BeyondTrust Remote Support and PRA pre-auth OS command injection

Beyondtrust · Privileged Remote Access

BeyondTrust Remote Support and certain older Privileged Remote Access versions contain an OS command injection flaw (CWE-78) reachable before authentication. A remote attacker can send crafted requests to execute operating system commands as the site user, which is severe given these products are remote-access gateways.

9.9 CVSS 4.0 Critical CISA KEV since 13 Feb 2026 Known ransomware use EPSS 91% · top 0.2% CWE-78 · OS command injection
9.9CVSS 4.0 base score
91%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
5References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted requests, an unauthenticated remote attacker may be able to execute operating system commands in the context of the site user.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityPre-authentication remote code execution with a 9.9 CVSS score, KEV listing with ransomware use, and near-maximum EPSS probability make this an urgent patch-first issue.

What it is

BeyondTrust Remote Support and certain older Privileged Remote Access versions contain an OS command injection flaw (CWE-78) reachable before authentication. A remote attacker can send crafted requests to execute operating system commands as the site user, which is severe given these products are remote-access gateways.

Impact

An unauthenticated attacker gains arbitrary OS command execution in the context of the site user, enabling host compromise and potential lateral movement into managed endpoints and privileged sessions.

Attack surface

Reachable over the network via crafted HTTP requests to the affected appliance; the CVSS 4.0 vector shows PR:N and UI:N, so no authentication or user interaction is required.

Exploitation

Listed in CISA KEV with a 2026-02-16 remediation due date and flagged for known ransomware campaign use; EPSS 30-day probability is 0.895 (99.8th percentile) and a public exploit reference exists.

What to do

  • Apply the vendor fixes per BeyondTrust advisory BT26-02 and KB0023293 immediately.
  • If patching cannot be completed by the KEV due date, restrict network access to the RS/PRA interfaces and follow BOD 22-01 guidance or discontinue use.
  • Isolate affected appliances from untrusted networks and limit management access to trusted administrative segments.
  • Rotate credentials and secrets that the site user account could access, and review for unauthorized changes.
  • Monitor vendor and CISA guidance for updated mitigations given active exploitation.

Detection

  • Hunt web and application logs for anomalous or malformed requests to RS/PRA endpoints preceding command execution.
  • Monitor for unexpected child processes spawned by the RS/PRA service account, especially shell or command interpreters.
  • Alert on outbound connections from RS/PRA hosts to unfamiliar external addresses.
  • Review authentication and session logs for activity inconsistent with normal administrative use.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2026-1731 to the Known Exploited Vulnerabilities catalog on 13 February 2026 as "BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 16 February 2026.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-1731 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-12356BeyondTrust PRA and RS unauthenticated command injectionBeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain a command injection flaw (CWE-77) that lets an unauthenticated attacker in…KEVEPSS 87%analysed7.2CVE-2024-12686BeyondTrust PRA and RS OS command injection by adminBeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain an OS command injection flaw (CWE-78). An attacker who already holds admin…KEVEPSS 14%analysed9.8CVE-2023-4310Beyondtrust privileged remote access command injection vulnerabilityBeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) versions 23.2.1 and 23.2.2 contain a command injection vulnerability which can be …EPSS 1.8%9.2CVE-2026-40138Beyondtrust privileged remote access improper authentication vulnerabilityA critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support and Privileged Remote Access. Improp…EPSS 0.46%9.2CVE-2026-40139Beyondtrust privileged remote access improper authentication vulnerabilityA critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. Improper processing of authenticati…EPSS 0.75%8.7CVE-2026-40140Beyondtrust privileged remote access uncontrolled resource consumption vulnerabilityBeyondTrust Remote Support and Privileged Remote Access contain a high-severity pre-authentication vulnerability in the network communication subsyst…EPSS 0.65%8.6CVE-2025-5309Beyondtrust privileged remote access code injection vulnerabilityThe chat feature within Remote Support (RS) and Privileged Remote Access (PRA) is vulnerable to a Server-Side Template Injection vulnerability which …EPSS 0.95%8.5CVE-2026-40141Beyondtrust privileged remote access vulnerabilityA high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote Access related to the process…EPSS 0.53%

Source: NIST National Vulnerability Database (record CVE-2026-1731), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.