Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.2
CVE-2026-40139: BeyondTrust Remote Support allows unauthorized access
CVE-2026-40139
CVE-2026-40139
Summary
An attacker can bypass security checks and gain access to BeyondTrust Remote Support, including accounts with high-level permissions, if a specific configuration is set up. This could lead to unauthorized access and potentially malicious actions. Update the configuration to fix this issue.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| beyondtrust | remote support |
< 26.2.1 < 26.1.1 |
| beyondtrust | privileged remote access |
< 26.2.1 < 26.1.1 |
| beyondtrust | privileged_remote_access |
< 25.3.3 cpe:2.3:a:beyondtrust:privileged_remote_access:*:*:*:*:*:*:*:* |
| beyondtrust | remote_support |
< 25.3.3 cpe:2.3:a:beyondtrust:remote_support:*:*:*:*:*:*:*:* |
Original title
A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. Improper processing of authentication requests may allow an unauthenticated remote ...
Original description
A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. Improper processing of authentication requests may allow an unauthenticated remote attacker to bypass access controls and gain unauthorized access to the appliance, including accounts with elevated privileges. Exploitation requires a specific authentication configuration to be enabled.
nvd CVSS4.0
9.2
Vulnerability type
CWE-287
Improper Authentication
Published: 6 Jul 2026 · Updated: 23 Jul 2026 · First seen: 6 Jul 2026