Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.5
CVE-2026-40141: BeyondTrust Remote Support: Unauthorized Data Access
CVE-2026-40141
CVE-2026-40141
Summary
A security weakness in BeyondTrust Remote Support and Privileged Remote Access could allow authorized users to access data they shouldn't see. This is a concern because it could compromise sensitive information. BeyondTrust should be updated to fix this issue.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| beyondtrust | remote support |
< 26.2.1 < 26.1.1 |
| beyondtrust | privilege remote access |
< 26.2.1 < 26.1.1 |
| beyondtrust | privileged_remote_access |
< 25.3.3 cpe:2.3:a:beyondtrust:privileged_remote_access:*:*:*:*:*:*:*:* |
| beyondtrust | remote_support |
< 25.3.3 cpe:2.3:a:beyondtrust:remote_support:*:*:*:*:*:*:*:* |
Original title
A high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote Access related to the processing of certain input parameters. Insufficient va...
Original description
A high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote Access related to the processing of certain input parameters. Insufficient validation of user-supplied input may allow an authenticated attacker with limited privileges to access unintended resources or data beyond their authorization scope. Exploitation is restricted to accounts with specific permissions.
nvd CVSS4.0
8.5
Vulnerability type
CWE-943
Published: 6 Jul 2026 · Updated: 23 Jul 2026 · First seen: 6 Jul 2026