CVE-2026-40139
BeyondTrust Privileged Remote Access Client Análise e mitigação de vulnerabilidades

Visão geral

CVE-2026-40139 is a critical pre-authentication authentication bypass vulnerability in the authentication subsystem of BeyondTrust Remote Support and Privileged Remote Access (PRA). Improper processing of authentication requests may allow an unauthenticated remote attacker to bypass access controls and gain unauthorized access to the appliance, including accounts with elevated privileges. Exploitation requires a specific authentication configuration to be enabled on the affected appliance. Both products are affected in versions up to and including 25.3.2 (fixed in 25.3.3), with cloud-hosted instances patched earlier. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical) and a CVSS v4.0 base score of 9.2 (Critical) (GitHub Advisory, BeyondTrust Advisory).

Detalhes técnicos

The vulnerability is classified as CWE-287 (Improper Authentication), meaning the product fails to adequately verify that an actor's claimed identity is legitimate during the authentication process (GitHub Advisory). The flaw resides in the authentication subsystem of BeyondTrust Remote Support and PRA, where improper processing of authentication requests enables an unauthenticated remote attacker to bypass access controls entirely over the network without requiring any privileges or user interaction. A key precondition is that a specific authentication configuration must be enabled on the appliance — the exact configuration is not publicly disclosed by BeyondTrust, limiting opportunistic exploitation. No public proof-of-concept code has been identified as of the time of reporting (BeyondTrust Advisory).

Impacto

Successful exploitation allows an unauthenticated remote attacker to gain unauthorized access to the BeyondTrust Remote Support or PRA appliance, including accounts with elevated privileges. This results in high impact to confidentiality, integrity, and availability of the vulnerable system, potentially enabling full administrative control over the remote access platform. Because BeyondTrust Remote Support and PRA are widely used in enterprise environments to manage privileged access to critical infrastructure, a compromise could facilitate lateral movement, credential harvesting, and access to downstream systems managed through the platform (GitHub Advisory, BeyondTrust Advisory).

Etapas de exploração

  1. Reconnaissance: Identify internet-facing BeyondTrust Remote Support or Privileged Remote Access appliances running versions 25.3.2 or earlier using tools such as Shodan or Censys, searching for BeyondTrust-specific banners or login pages.
  2. Identify authentication configuration: Determine whether the target appliance has the specific authentication configuration enabled that is required for exploitation (the exact configuration is not publicly disclosed; attackers may probe for non-standard authentication endpoints or methods).
  3. Craft malicious authentication request: Send a specially crafted authentication request to the appliance's authentication subsystem that exploits the improper processing logic, bypassing normal credential validation.
  4. Bypass access controls: The improper authentication handling allows the attacker to authenticate without valid credentials, gaining access to the appliance including elevated privilege accounts.
  5. Post-exploitation: With privileged access to the BeyondTrust appliance, the attacker can access managed endpoints, harvest credentials, establish persistence, or pivot laterally to systems managed through the remote support platform (GitHub Advisory, BeyondTrust Advisory).

Indicadores de compromisso

  • Network: Unexpected or anomalous authentication requests to the BeyondTrust Remote Support or PRA appliance from unknown or untrusted IP addresses; successful authentication events originating from external or unusual sources without corresponding legitimate user activity.
  • Logs: Authentication success events in appliance logs for privileged accounts with no corresponding MFA or expected credential usage; login events at unusual times or from unexpected geographic locations; absence of expected authentication steps (e.g., missing password validation log entries).
  • Process/Session: Unexpected administrative sessions or configuration changes on the BeyondTrust appliance; new user accounts or privilege escalations performed shortly after anomalous authentication events.
  • File System: Unexpected changes to appliance configuration files or authentication settings; new scheduled tasks or scripts added to the appliance system.

Mitigação e soluções alternativas

BeyondTrust has released version 25.3.3 for both Remote Support and Privileged Remote Access, which addresses this vulnerability; organizations should upgrade immediately (BeyondTrust Advisory). Cloud-hosted BeyondTrust instances were patched earlier (by version 26.2.1 per ENISA data). As a workaround, administrators should review and restrict the specific authentication configuration that enables exploitation — disabling non-essential authentication methods reduces exposure. Additionally, implementing network access controls to limit appliance access to trusted IP ranges and monitoring for anomalous authentication activity are recommended interim measures (GitHub Advisory).

Reações da comunidade

The vulnerability received broad coverage from security media outlets including BleepingComputer, The Hacker News, and CybersecurityNews, with multiple articles highlighting the critical severity and the risk to enterprise remote access infrastructure (BleepingComputer, The Hacker News). The SANS Internet Storm Center discussed the vulnerability in a podcast episode, and national CERTs including Ireland's NCSC and Singapore's CSA issued advisories urging prompt patching. Community discussion on Reddit and social platforms (Bluesky, Mastodon) noted the significance given BeyondTrust's prior high-profile exploitation history (e.g., CVE-2024-12356). Beazley Security Labs published an independent advisory (BSL-A1186), and SOCRadar and CyCognito produced threat intelligence analyses covering the vulnerability alongside the related CVE-2026-40138.

Recursos adicionais


OrigemEste relatório foi gerado usando IA

Relacionado BeyondTrust Privileged Remote Access Client Vulnerabilidades:

CVE ID

Gravidade

Pontuação

Tecnologias

Nome do componente

Exploração do CISA KEV

Tem correção

Data de publicação

CVE-2026-1731CRITICAL9.9
  • BeyondTrust Privileged Remote Access Client logoBeyondTrust Privileged Remote Access Client
  • cpe:2.3:a:beyondtrust:privileged_remote_access
SimSimFeb 06, 2026
CVE-2026-40139CRITICAL9.2
  • BeyondTrust Privileged Remote Access Client logoBeyondTrust Privileged Remote Access Client
  • cpe:2.3:a:beyondtrust:remote_support
NãoSimJul 06, 2026
CVE-2026-40138CRITICAL9.2
  • BeyondTrust Privileged Remote Access Client logoBeyondTrust Privileged Remote Access Client
  • cpe:2.3:a:beyondtrust:privileged_remote_access
NãoSimJul 06, 2026
CVE-2026-40140HIGH8.7
  • BeyondTrust Privileged Remote Access Client logoBeyondTrust Privileged Remote Access Client
  • cpe:2.3:a:beyondtrust:remote_support
NãoSimJul 06, 2026
CVE-2026-40141HIGH8.5
  • BeyondTrust Privileged Remote Access Client logoBeyondTrust Privileged Remote Access Client
  • cpe:2.3:a:beyondtrust:privileged_remote_access
NãoSimJul 06, 2026

Avaliação de vulnerabilidade gratuita

Compare sua postura de segurança na nuvem

Avalie suas práticas de segurança na nuvem em 9 domínios de segurança para comparar seu nível de risco e identificar lacunas em suas defesas.

Solicitar avaliação

Marque uma demonstração personalizada

Pronto para ver a Wiz em ação?

"A melhor experiência do usuário que eu já vi, fornece visibilidade total para cargas de trabalho na nuvem."
David EstlickCISO
"A Wiz fornece um único painel de vidro para ver o que está acontecendo em nossos ambientes de nuvem."
Adam FletcherDiretor de Segurança
"Sabemos que se a Wiz identifica algo como crítico, na verdade é."
Greg PoniatowskiChefe de Gerenciamento de Ameaças e Vulnerabilidades