
PEACH
Uma estrutura de isolamento de inquilino
CVE-2026-40140 is a pre-authentication denial-of-service vulnerability in BeyondTrust Remote Support and Privileged Remote Access, located in the network communication subsystem. Insufficient validation of client-supplied input allows an unauthenticated remote attacker to trigger a denial-of-service condition affecting appliance availability. Affected versions are Remote Support and Privileged Remote Access up to and including 25.3.2 (fixed in 25.3.3); some sources also reference a fix in 26.2.1 for certain product lines. It was published on July 6, 2026, with a CVSS v3.1 score of 7.5 (High) and a CVSS v4.0 score of 8.7 (High) (GitHub Advisory, BeyondTrust Advisory).
The vulnerability is classified as CWE-400 (Uncontrolled Resource Consumption), meaning the affected network communication subsystem fails to properly control the allocation or maintenance of resources when processing client-supplied input. An unauthenticated attacker can send specially crafted network requests to the appliance, causing resource exhaustion or a crash that disrupts service availability. No authentication or user interaction is required, and the attack can be launched remotely over the network with low complexity. Attack patterns associated with this vulnerability include XML Ping of the Death (CAPEC-147) and Regular Expression Exponential Blowup (CAPEC-492), suggesting the flaw may involve malformed or resource-intensive input parsing (GitHub Advisory, BeyondTrust Advisory).
Successful exploitation results in a denial-of-service condition that disrupts the availability of BeyondTrust Remote Support and Privileged Remote Access appliances. There is no impact to confidentiality or integrity — the vulnerability is limited to availability. Because BeyondTrust Remote Support and Privileged Remote Access are enterprise remote access platforms often used for privileged session management, an outage could prevent administrators and support staff from accessing critical systems, potentially impacting business continuity and incident response capabilities (GitHub Advisory, BeyondTrust Advisory).
BeyondTrust has released patched versions 25.3.3 (and 26.2.1 for certain product lines) for both Remote Support and Privileged Remote Access; upgrading to these versions is the primary recommended remediation (BeyondTrust Advisory). As a network-based workaround, organizations should implement network-level access controls (firewalls, allowlists) to restrict connectivity to BeyondTrust appliances to trusted networks and IP ranges only. Additionally, monitor appliance availability and configure alerting for unexpected service disruptions to enable rapid detection and response.
The vulnerability received broad coverage from security media outlets including BleepingComputer, The Hacker News, SC World, and CybersecurityNews, often grouped with related BeyondTrust CVEs (CVE-2026-40138, CVE-2026-40139) disclosed in the same advisory (BleepingComputer, The Hacker News). National CERTs including Singapore's CSA and Thailand's ThaiCERT issued advisories urging organizations to patch promptly. Community discussion on Mastodon and Bluesky noted the significance of pre-authentication vulnerabilities in privileged access management tools given BeyondTrust's history of high-profile exploitation in 2024–2025.
Origem: Este relatório foi gerado usando IA
Avaliação de vulnerabilidade gratuita
Avalie suas práticas de segurança na nuvem em 9 domínios de segurança para comparar seu nível de risco e identificar lacunas em suas defesas.
Marque uma demonstração personalizada
"A melhor experiência do usuário que eu já vi, fornece visibilidade total para cargas de trabalho na nuvem."
"A Wiz fornece um único painel de vidro para ver o que está acontecendo em nossos ambientes de nuvem."
"Sabemos que se a Wiz identifica algo como crítico, na verdade é."