
PEACH
Uma estrutura de isolamento de inquilino
CVE-2026-40139 is a critical pre-authentication authentication bypass vulnerability in the authentication subsystem of BeyondTrust Remote Support and Privileged Remote Access (PRA). Improper processing of authentication requests may allow an unauthenticated remote attacker to bypass access controls and gain unauthorized access to the appliance, including accounts with elevated privileges. Exploitation requires a specific authentication configuration to be enabled on the affected appliance. Both products are affected in versions up to and including 25.3.2 (fixed in 25.3.3), with cloud-hosted instances patched earlier. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical) and a CVSS v4.0 base score of 9.2 (Critical) (GitHub Advisory, BeyondTrust Advisory).
The vulnerability is classified as CWE-287 (Improper Authentication), meaning the product fails to adequately verify that an actor's claimed identity is legitimate during the authentication process (GitHub Advisory). The flaw resides in the authentication subsystem of BeyondTrust Remote Support and PRA, where improper processing of authentication requests enables an unauthenticated remote attacker to bypass access controls entirely over the network without requiring any privileges or user interaction. A key precondition is that a specific authentication configuration must be enabled on the appliance — the exact configuration is not publicly disclosed by BeyondTrust, limiting opportunistic exploitation. No public proof-of-concept code has been identified as of the time of reporting (BeyondTrust Advisory).
Successful exploitation allows an unauthenticated remote attacker to gain unauthorized access to the BeyondTrust Remote Support or PRA appliance, including accounts with elevated privileges. This results in high impact to confidentiality, integrity, and availability of the vulnerable system, potentially enabling full administrative control over the remote access platform. Because BeyondTrust Remote Support and PRA are widely used in enterprise environments to manage privileged access to critical infrastructure, a compromise could facilitate lateral movement, credential harvesting, and access to downstream systems managed through the platform (GitHub Advisory, BeyondTrust Advisory).
BeyondTrust has released version 25.3.3 for both Remote Support and Privileged Remote Access, which addresses this vulnerability; organizations should upgrade immediately (BeyondTrust Advisory). Cloud-hosted BeyondTrust instances were patched earlier (by version 26.2.1 per ENISA data). As a workaround, administrators should review and restrict the specific authentication configuration that enables exploitation — disabling non-essential authentication methods reduces exposure. Additionally, implementing network access controls to limit appliance access to trusted IP ranges and monitoring for anomalous authentication activity are recommended interim measures (GitHub Advisory).
The vulnerability received broad coverage from security media outlets including BleepingComputer, The Hacker News, and CybersecurityNews, with multiple articles highlighting the critical severity and the risk to enterprise remote access infrastructure (BleepingComputer, The Hacker News). The SANS Internet Storm Center discussed the vulnerability in a podcast episode, and national CERTs including Ireland's NCSC and Singapore's CSA issued advisories urging prompt patching. Community discussion on Reddit and social platforms (Bluesky, Mastodon) noted the significance given BeyondTrust's prior high-profile exploitation history (e.g., CVE-2024-12356). Beazley Security Labs published an independent advisory (BSL-A1186), and SOCRadar and CyCognito produced threat intelligence analyses covering the vulnerability alongside the related CVE-2026-40138.
Origem: Este relatório foi gerado usando IA
Avaliação de vulnerabilidade gratuita
Avalie suas práticas de segurança na nuvem em 9 domínios de segurança para comparar seu nível de risco e identificar lacunas em suas defesas.
Marque uma demonstração personalizada
"A melhor experiência do usuário que eu já vi, fornece visibilidade total para cargas de trabalho na nuvem."
"A Wiz fornece um único painel de vidro para ver o que está acontecendo em nossos ambientes de nuvem."
"Sabemos que se a Wiz identifica algo como crítico, na verdade é."