CVE-2026-40138
BeyondTrust Privileged Remote Access Client vulnerability analysis and mitigation

Overview

CVE-2026-40138 is a critical pre-authentication authentication bypass vulnerability in the authentication subsystem of BeyondTrust Remote Support and Privileged Remote Access (PRA). Improper validation of authentication data may allow a network-positioned attacker to bypass access controls and gain unauthorized access to the appliance, including accounts with elevated privileges. Exploitation requires a specific authentication configuration to be enabled on the target appliance. All versions up to and including 25.3.2 of both products are affected; version 25.3.3 and later are patched. It carries a CVSS v3.1 base score of 8.1 (High) and a CVSS v4.0 base score of 9.2 (Critical) (GitHub Advisory, BeyondTrust Advisory).

Technical details

The vulnerability is classified as CWE-287 (Improper Authentication), rooted in insufficient validation of authentication data within the BeyondTrust authentication subsystem. An unauthenticated, network-positioned attacker can exploit this flaw to bypass access controls without requiring any user interaction or prior privileges, though exploitation is contingent on a specific authentication configuration being enabled on the appliance. The attack complexity is rated High due to this prerequisite configuration requirement. A public proof-of-concept walkthrough has been published by security researcher Deniz Halil, providing technical details on the exploitation mechanics (GitHub Advisory, Deniz Halil PoC).

Impact

Successful exploitation allows an unauthenticated remote attacker to gain unauthorized access to the BeyondTrust appliance, including accounts with elevated privileges, resulting in high confidentiality, integrity, and availability impact on the vulnerable system. An attacker with access to privileged remote access infrastructure could pivot to managed endpoints, exfiltrate sensitive credentials or session data, and potentially achieve full control over enterprise remote access systems. Given that BeyondTrust products are commonly used to manage privileged access across enterprise environments, compromise of these appliances poses significant lateral movement risk (GitHub Advisory, BeyondTrust Advisory).

Exploitability

A proof-of-concept write-up has been published by researcher Deniz Halil as of July 10, 2026, providing exploitation details (Deniz Halil PoC). The EPSS score is approximately 0.42%, placing it in the 34th percentile for exploitation probability within 30 days. As of the time of reporting, NVD SSVC data indicates exploitation status as "none" confirmed in the wild, and the vulnerability has not been added to the CISA KEV catalog. No threat actor attribution has been publicly reported. The vulnerability is not automatable due to the required specific authentication configuration precondition (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing BeyondTrust Remote Support or Privileged Remote Access appliances running versions 25.3.2 or earlier using tools such as Shodan or Censys, targeting known BeyondTrust web interface fingerprints.
  2. Identify authentication configuration: Determine whether the target appliance has the specific vulnerable authentication configuration enabled (e.g., a particular external authentication provider or SSO integration), which is a prerequisite for exploitation.
  3. Craft malicious authentication request: Construct an HTTP request to the authentication subsystem endpoint that supplies improperly validated authentication data — exploiting the lack of sufficient validation to assert a false identity or bypass credential checks.
  4. Bypass access controls: Submit the crafted request to the appliance; due to improper validation (CWE-287), the appliance accepts the authentication claim without proper verification, granting access.
  5. Access elevated accounts: Leverage the bypassed authentication to access accounts with elevated privileges on the appliance, enabling session hijacking, credential harvesting, or further lateral movement into managed endpoints (Deniz Halil PoC, GitHub Advisory).

Indicators of compromise

  • Network: Unexpected or anomalous authentication requests to BeyondTrust Remote Support or PRA web interfaces from unknown or external IP addresses; authentication attempts that succeed without valid credentials in network logs.
  • Logs: Authentication success events in BeyondTrust appliance logs with no corresponding valid credential submission; login events for privileged accounts from unusual source IPs or at unusual times; errors or anomalies in the authentication subsystem logs around the time of suspected exploitation.
  • Process/Session: Unexpected privileged sessions initiated on the BeyondTrust appliance; new administrative accounts or configuration changes made without corresponding authorized change records.
  • File System: Unexpected configuration changes to authentication settings on the appliance; new or modified files in the BeyondTrust installation directory not associated with a known update (Deniz Halil PoC, BeyondTrust Advisory).

Mitigation and workarounds

BeyondTrust has released version 25.3.3 for both Remote Support and Privileged Remote Access, which addresses this vulnerability; organizations should upgrade immediately (BeyondTrust Advisory). As an interim measure where immediate patching is not possible, administrators should review and disable the specific authentication configuration that enables exploitation, implement network segmentation to restrict access to BeyondTrust appliances, and monitor for unauthorized access attempts. Cloud-hosted BeyondTrust instances were patched automatically by the vendor. Prioritize patching self-hosted deployments, as these remain exposed until manually updated (GitHub Advisory, BleepingComputer).

Community reactions

BeyondTrust published security advisory BT26-03 disclosing the vulnerability and providing patching guidance (BeyondTrust Advisory). The Hacker News, BleepingComputer, and multiple cybersecurity news outlets covered the disclosure prominently, noting the critical severity and the risk to enterprise remote access infrastructure (The Hacker News, BleepingComputer). National CERTs including Ireland's NCSC and Singapore's CSA issued advisories urging organizations to patch immediately. Community discussion on Reddit and social media highlighted concern over the privileged access nature of the affected products and the availability of a public PoC write-up.

Additional resources


SourceThis report was generated using AI

Related BeyondTrust Privileged Remote Access Client vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-1731CRITICAL9.9
  • BeyondTrust Privileged Remote Access Client logoBeyondTrust Privileged Remote Access Client
  • cpe:2.3:a:beyondtrust:privileged_remote_access
YesYesFeb 06, 2026
CVE-2026-40139CRITICAL9.2
  • BeyondTrust Privileged Remote Access Client logoBeyondTrust Privileged Remote Access Client
  • cpe:2.3:a:beyondtrust:privileged_remote_access
NoYesJul 06, 2026
CVE-2026-40138CRITICAL9.2
  • BeyondTrust Privileged Remote Access Client logoBeyondTrust Privileged Remote Access Client
  • cpe:2.3:a:beyondtrust:privileged_remote_access
NoYesJul 06, 2026
CVE-2026-40140HIGH8.7
  • BeyondTrust Privileged Remote Access Client logoBeyondTrust Privileged Remote Access Client
  • cpe:2.3:a:beyondtrust:privileged_remote_access
NoYesJul 06, 2026
CVE-2026-40141HIGH8.5
  • BeyondTrust Privileged Remote Access Client logoBeyondTrust Privileged Remote Access Client
  • cpe:2.3:a:beyondtrust:privileged_remote_access
NoYesJul 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management