
PEACH
Uma estrutura de isolamento de inquilino
CVE-2026-40138 is a critical pre-authentication authentication bypass vulnerability in the authentication subsystem of BeyondTrust Remote Support and Privileged Remote Access (PRA). Improper validation of authentication data may allow a network-positioned attacker to bypass access controls and gain unauthorized access to the appliance, including accounts with elevated privileges. Exploitation requires a specific authentication configuration to be enabled on the target appliance. All versions up to and including 25.3.2 of both products are affected; version 25.3.3 and later are patched. It carries a CVSS v3.1 base score of 8.1 (High) and a CVSS v4.0 base score of 9.2 (Critical) (GitHub Advisory, BeyondTrust Advisory).
The vulnerability is classified as CWE-287 (Improper Authentication), rooted in insufficient validation of authentication data within the BeyondTrust authentication subsystem. An unauthenticated, network-positioned attacker can exploit this flaw to bypass access controls without requiring any user interaction or prior privileges, though exploitation is contingent on a specific authentication configuration being enabled on the appliance. The attack complexity is rated High due to this prerequisite configuration requirement. A public proof-of-concept walkthrough has been published by security researcher Deniz Halil, providing technical details on the exploitation mechanics (GitHub Advisory, Deniz Halil PoC).
Successful exploitation allows an unauthenticated remote attacker to gain unauthorized access to the BeyondTrust appliance, including accounts with elevated privileges, resulting in high confidentiality, integrity, and availability impact on the vulnerable system. An attacker with access to privileged remote access infrastructure could pivot to managed endpoints, exfiltrate sensitive credentials or session data, and potentially achieve full control over enterprise remote access systems. Given that BeyondTrust products are commonly used to manage privileged access across enterprise environments, compromise of these appliances poses significant lateral movement risk (GitHub Advisory, BeyondTrust Advisory).
BeyondTrust has released version 25.3.3 for both Remote Support and Privileged Remote Access, which addresses this vulnerability; organizations should upgrade immediately (BeyondTrust Advisory). As an interim measure where immediate patching is not possible, administrators should review and disable the specific authentication configuration that enables exploitation, implement network segmentation to restrict access to BeyondTrust appliances, and monitor for unauthorized access attempts. Cloud-hosted BeyondTrust instances were patched automatically by the vendor. Prioritize patching self-hosted deployments, as these remain exposed until manually updated (GitHub Advisory, BleepingComputer).
BeyondTrust published security advisory BT26-03 disclosing the vulnerability and providing patching guidance (BeyondTrust Advisory). The Hacker News, BleepingComputer, and multiple cybersecurity news outlets covered the disclosure prominently, noting the critical severity and the risk to enterprise remote access infrastructure (The Hacker News, BleepingComputer). National CERTs including Ireland's NCSC and Singapore's CSA issued advisories urging organizations to patch immediately. Community discussion on Reddit and social media highlighted concern over the privileged access nature of the affected products and the availability of a public PoC write-up.
Origem: Este relatório foi gerado usando IA
Avaliação de vulnerabilidade gratuita
Avalie suas práticas de segurança na nuvem em 9 domínios de segurança para comparar seu nível de risco e identificar lacunas em suas defesas.
Marque uma demonstração personalizada
"A melhor experiência do usuário que eu já vi, fornece visibilidade total para cargas de trabalho na nuvem."
"A Wiz fornece um único painel de vidro para ver o que está acontecendo em nossos ambientes de nuvem."
"Sabemos que se a Wiz identifica algo como crítico, na verdade é."