CVE-2026-40138
BeyondTrust Privileged Remote Access Client Análise e mitigação de vulnerabilidades

Visão geral

CVE-2026-40138 is a critical pre-authentication authentication bypass vulnerability in the authentication subsystem of BeyondTrust Remote Support and Privileged Remote Access (PRA). Improper validation of authentication data may allow a network-positioned attacker to bypass access controls and gain unauthorized access to the appliance, including accounts with elevated privileges. Exploitation requires a specific authentication configuration to be enabled on the target appliance. All versions up to and including 25.3.2 of both products are affected; version 25.3.3 and later are patched. It carries a CVSS v3.1 base score of 8.1 (High) and a CVSS v4.0 base score of 9.2 (Critical) (GitHub Advisory, BeyondTrust Advisory).

Detalhes técnicos

The vulnerability is classified as CWE-287 (Improper Authentication), rooted in insufficient validation of authentication data within the BeyondTrust authentication subsystem. An unauthenticated, network-positioned attacker can exploit this flaw to bypass access controls without requiring any user interaction or prior privileges, though exploitation is contingent on a specific authentication configuration being enabled on the appliance. The attack complexity is rated High due to this prerequisite configuration requirement. A public proof-of-concept walkthrough has been published by security researcher Deniz Halil, providing technical details on the exploitation mechanics (GitHub Advisory, Deniz Halil PoC).

Impacto

Successful exploitation allows an unauthenticated remote attacker to gain unauthorized access to the BeyondTrust appliance, including accounts with elevated privileges, resulting in high confidentiality, integrity, and availability impact on the vulnerable system. An attacker with access to privileged remote access infrastructure could pivot to managed endpoints, exfiltrate sensitive credentials or session data, and potentially achieve full control over enterprise remote access systems. Given that BeyondTrust products are commonly used to manage privileged access across enterprise environments, compromise of these appliances poses significant lateral movement risk (GitHub Advisory, BeyondTrust Advisory).

Etapas de exploração

  1. Reconnaissance: Identify internet-facing BeyondTrust Remote Support or Privileged Remote Access appliances running versions 25.3.2 or earlier using tools such as Shodan or Censys, targeting known BeyondTrust web interface fingerprints.
  2. Identify authentication configuration: Determine whether the target appliance has the specific vulnerable authentication configuration enabled (e.g., a particular external authentication provider or SSO integration), which is a prerequisite for exploitation.
  3. Craft malicious authentication request: Construct an HTTP request to the authentication subsystem endpoint that supplies improperly validated authentication data — exploiting the lack of sufficient validation to assert a false identity or bypass credential checks.
  4. Bypass access controls: Submit the crafted request to the appliance; due to improper validation (CWE-287), the appliance accepts the authentication claim without proper verification, granting access.
  5. Access elevated accounts: Leverage the bypassed authentication to access accounts with elevated privileges on the appliance, enabling session hijacking, credential harvesting, or further lateral movement into managed endpoints (Deniz Halil PoC, GitHub Advisory).

Indicadores de compromisso

  • Network: Unexpected or anomalous authentication requests to BeyondTrust Remote Support or PRA web interfaces from unknown or external IP addresses; authentication attempts that succeed without valid credentials in network logs.
  • Logs: Authentication success events in BeyondTrust appliance logs with no corresponding valid credential submission; login events for privileged accounts from unusual source IPs or at unusual times; errors or anomalies in the authentication subsystem logs around the time of suspected exploitation.
  • Process/Session: Unexpected privileged sessions initiated on the BeyondTrust appliance; new administrative accounts or configuration changes made without corresponding authorized change records.
  • File System: Unexpected configuration changes to authentication settings on the appliance; new or modified files in the BeyondTrust installation directory not associated with a known update (Deniz Halil PoC, BeyondTrust Advisory).

Mitigação e soluções alternativas

BeyondTrust has released version 25.3.3 for both Remote Support and Privileged Remote Access, which addresses this vulnerability; organizations should upgrade immediately (BeyondTrust Advisory). As an interim measure where immediate patching is not possible, administrators should review and disable the specific authentication configuration that enables exploitation, implement network segmentation to restrict access to BeyondTrust appliances, and monitor for unauthorized access attempts. Cloud-hosted BeyondTrust instances were patched automatically by the vendor. Prioritize patching self-hosted deployments, as these remain exposed until manually updated (GitHub Advisory, BleepingComputer).

Reações da comunidade

BeyondTrust published security advisory BT26-03 disclosing the vulnerability and providing patching guidance (BeyondTrust Advisory). The Hacker News, BleepingComputer, and multiple cybersecurity news outlets covered the disclosure prominently, noting the critical severity and the risk to enterprise remote access infrastructure (The Hacker News, BleepingComputer). National CERTs including Ireland's NCSC and Singapore's CSA issued advisories urging organizations to patch immediately. Community discussion on Reddit and social media highlighted concern over the privileged access nature of the affected products and the availability of a public PoC write-up.

Recursos adicionais


OrigemEste relatório foi gerado usando IA

Relacionado BeyondTrust Privileged Remote Access Client Vulnerabilidades:

CVE ID

Gravidade

Pontuação

Tecnologias

Nome do componente

Exploração do CISA KEV

Tem correção

Data de publicação

CVE-2026-1731CRITICAL9.9
  • BeyondTrust Privileged Remote Access Client logoBeyondTrust Privileged Remote Access Client
  • cpe:2.3:a:beyondtrust:privileged_remote_access
SimSimFeb 06, 2026
CVE-2026-40139CRITICAL9.2
  • BeyondTrust Privileged Remote Access Client logoBeyondTrust Privileged Remote Access Client
  • cpe:2.3:a:beyondtrust:remote_support
NãoSimJul 06, 2026
CVE-2026-40138CRITICAL9.2
  • BeyondTrust Privileged Remote Access Client logoBeyondTrust Privileged Remote Access Client
  • cpe:2.3:a:beyondtrust:privileged_remote_access
NãoSimJul 06, 2026
CVE-2026-40140HIGH8.7
  • BeyondTrust Privileged Remote Access Client logoBeyondTrust Privileged Remote Access Client
  • cpe:2.3:a:beyondtrust:remote_support
NãoSimJul 06, 2026
CVE-2026-40141HIGH8.5
  • BeyondTrust Privileged Remote Access Client logoBeyondTrust Privileged Remote Access Client
  • cpe:2.3:a:beyondtrust:privileged_remote_access
NãoSimJul 06, 2026

Avaliação de vulnerabilidade gratuita

Compare sua postura de segurança na nuvem

Avalie suas práticas de segurança na nuvem em 9 domínios de segurança para comparar seu nível de risco e identificar lacunas em suas defesas.

Solicitar avaliação

Marque uma demonstração personalizada

Pronto para ver a Wiz em ação?

"A melhor experiência do usuário que eu já vi, fornece visibilidade total para cargas de trabalho na nuvem."
David EstlickCISO
"A Wiz fornece um único painel de vidro para ver o que está acontecendo em nossos ambientes de nuvem."
Adam FletcherDiretor de Segurança
"Sabemos que se a Wiz identifica algo como crítico, na verdade é."
Greg PoniatowskiChefe de Gerenciamento de Ameaças e Vulnerabilidades