
PEACH
Uma estrutura de isolamento de inquilino
CVE-2026-40141 is a high-severity authorization bypass vulnerability in BeyondTrust Remote Support and Privileged Remote Access (PRA) caused by insufficient validation of user-supplied input parameters in a web application component. It affects all versions of both products up to and including 25.3.2 (fixed in 25.3.3). The vulnerability was published on July 6, 2026, with a patch released the same day. It carries a CVSS v3.1 base score of 9.9 (Critical) and a CVSS v4.0 base score of 8.5 (High) (GitHub Advisory, BeyondTrust Advisory).
The root cause is classified as CWE-943 (Improper Neutralization of Special Elements in Data Query Logic), which maps to CAPEC-676 (NoSQL Injection), indicating that the vulnerability likely involves manipulation of query logic through crafted input parameters in the web application layer (GitHub Advisory). An authenticated attacker with limited, specific permissions can supply specially crafted input to a vulnerable web component, causing the application to process queries or access resources outside the attacker's authorized scope. Exploitation requires network access and a valid low-privilege account with specific permissions, but no user interaction or elevated complexity is needed (BeyondTrust Advisory).
Successful exploitation allows an authenticated attacker with limited privileges to access unintended resources and data beyond their authorization scope, resulting in high confidentiality impact on both the vulnerable and subsequent systems. The CVSS v4.0 scoring also reflects high integrity and availability impact on subsequent systems, suggesting the vulnerability could be leveraged to affect connected infrastructure or managed endpoints. Given that BeyondTrust Remote Support and PRA are privileged access management tools used in enterprise environments, unauthorized access could expose sensitive credentials, session data, or managed systems, with significant potential for lateral movement (GitHub Advisory, BeyondTrust Advisory).
BeyondTrust released a patch on July 6, 2026; organizations should upgrade both Remote Support and Privileged Remote Access to version 25.3.3 or later (BeyondTrust Advisory). As interim measures, administrators should review and restrict user permissions to the minimum necessary for job functions, and monitor access logs for unauthorized resource access attempts. Implementing additional input validation and authorization checks at the application layer can further reduce risk until patching is complete.
The vulnerability received broad coverage from security media outlets including BleepingComputer, The Hacker News, GBHackers, and CyberSecurityNews, with many articles framing it alongside related BeyondTrust flaws (notably CVE-2026-40138) as a cluster of critical authentication and authorization bypass issues (BleepingComputer, The Hacker News). Government CERTs including Singapore's CSA and Thailand's ThaiCERT issued advisories urging prompt patching. The H-ISAC also published a TLP:WHITE vulnerability bulletin for the healthcare sector. Community sentiment reflects urgency given BeyondTrust's history of high-profile exploitation (e.g., the 2024 BeyondTrust breach), though no active exploitation of this specific CVE has been observed.
Origem: Este relatório foi gerado usando IA
Avaliação de vulnerabilidade gratuita
Avalie suas práticas de segurança na nuvem em 9 domínios de segurança para comparar seu nível de risco e identificar lacunas em suas defesas.
Marque uma demonstração personalizada
"A melhor experiência do usuário que eu já vi, fornece visibilidade total para cargas de trabalho na nuvem."
"A Wiz fornece um único painel de vidro para ver o que está acontecendo em nossos ambientes de nuvem."
"Sabemos que se a Wiz identifica algo como crítico, na verdade é."