Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.2

CVE-2026-40139: BeyondTrust Remote Support allows unauthorized access

CVE-2026-40139 CVE-2026-40139
Summary

An attacker can bypass security checks and gain access to BeyondTrust Remote Support, including accounts with high-level permissions, if a specific configuration is set up. This could lead to unauthorized access and potentially malicious actions. Update the configuration to fix this issue.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
beyondtrust remote support < 26.2.1
< 26.1.1
beyondtrust privileged remote access < 26.2.1
< 26.1.1
beyondtrust privileged_remote_access < 25.3.3
cpe:2.3:a:beyondtrust:privileged_remote_access:*:*:*:*:*:*:*:*
beyondtrust remote_support < 25.3.3
cpe:2.3:a:beyondtrust:remote_support:*:*:*:*:*:*:*:*
Original title
A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. Improper processing of authentication requests may allow an unauthenticated remote ...
Original description
A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. Improper processing of authentication requests may allow an unauthenticated remote attacker to bypass access controls and gain unauthorized access to the appliance, including accounts with elevated privileges. Exploitation requires a specific authentication configuration to be enabled.
nvd CVSS4.0 9.2
Vulnerability type
CWE-287 Improper Authentication
Published: 6 Jul 2026 · Updated: 23 Jul 2026 · First seen: 6 Jul 2026