← Vulnerability feed

Vulnerability record · CVE-2026-40141 · published 6 July 2026

CVE-2026-40141: Beyondtrust privileged remote access vulnerability

Beyondtrust · Privileged Remote Access

A high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote Access related to the processing of certain input parameters. Insufficient validation of user-supplied input may allow an authenticated attacker with limited privileges to access unintended resources or data beyond their authorization scope. Exploitation is restricted to accounts with specific permissions.

8.5 CVSS 4.0 High EPSS 0.53% · top 57.5% CWE-943 · CWE-943
8.5CVSS 4.0 base score
0.53%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
1References
7 Jul 2026Last modified by NVD

Description

A high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote Access related to the processing of certain input parameters. Insufficient validation of user-supplied input may allow an authenticated attacker with limited privileges to access unintended resources or data beyond their authorization scope. Exploitation is restricted to accounts with specific permissions.

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-40141 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2026-1731BeyondTrust Remote Support and PRA pre-auth OS command injectionBeyondTrust Remote Support and certain older Privileged Remote Access versions contain an OS command injection flaw (CWE-78) reachable before authent…KEVEPSS 91%analysed9.8CVE-2024-12356BeyondTrust PRA and RS unauthenticated command injectionBeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain a command injection flaw (CWE-77) that lets an unauthenticated attacker in…KEVEPSS 87%analysed7.2CVE-2024-12686BeyondTrust PRA and RS OS command injection by adminBeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain an OS command injection flaw (CWE-78). An attacker who already holds admin…KEVEPSS 14%analysed9.8CVE-2023-4310Beyondtrust privileged remote access command injection vulnerabilityBeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) versions 23.2.1 and 23.2.2 contain a command injection vulnerability which can be …EPSS 1.8%9.2CVE-2026-40138Beyondtrust privileged remote access improper authentication vulnerabilityA critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support and Privileged Remote Access. Improp…EPSS 0.46%9.2CVE-2026-40139Beyondtrust privileged remote access improper authentication vulnerabilityA critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. Improper processing of authenticati…EPSS 0.75%8.7CVE-2026-40140Beyondtrust privileged remote access uncontrolled resource consumption vulnerabilityBeyondTrust Remote Support and Privileged Remote Access contain a high-severity pre-authentication vulnerability in the network communication subsyst…EPSS 0.65%8.6CVE-2025-5309Beyondtrust privileged remote access code injection vulnerabilityThe chat feature within Remote Support (RS) and Privileged Remote Access (PRA) is vulnerable to a Server-Side Template Injection vulnerability which …EPSS 0.95%

Source: NIST National Vulnerability Database (record CVE-2026-40141), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.