
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-40138 is a critical pre-authentication authentication bypass vulnerability in the authentication subsystem of BeyondTrust Remote Support and Privileged Remote Access (PRA). Improper validation of authentication data may allow a network-positioned attacker to bypass access controls and gain unauthorized access to the appliance, including accounts with elevated privileges. Exploitation requires a specific authentication configuration to be enabled on the target appliance. All versions up to and including 25.3.2 of both products are affected; version 25.3.3 and later are patched. It carries a CVSS v3.1 base score of 8.1 (High) and a CVSS v4.0 base score of 9.2 (Critical) (GitHub Advisory, BeyondTrust Advisory).
The vulnerability is classified as CWE-287 (Improper Authentication), rooted in insufficient validation of authentication data within the BeyondTrust authentication subsystem. An unauthenticated, network-positioned attacker can exploit this flaw to bypass access controls without requiring any user interaction or prior privileges, though exploitation is contingent on a specific authentication configuration being enabled on the appliance. The attack complexity is rated High due to this prerequisite configuration requirement. A public proof-of-concept walkthrough has been published by security researcher Deniz Halil, providing technical details on the exploitation mechanics (GitHub Advisory, Deniz Halil PoC).
Successful exploitation allows an unauthenticated remote attacker to gain unauthorized access to the BeyondTrust appliance, including accounts with elevated privileges, resulting in high confidentiality, integrity, and availability impact on the vulnerable system. An attacker with access to privileged remote access infrastructure could pivot to managed endpoints, exfiltrate sensitive credentials or session data, and potentially achieve full control over enterprise remote access systems. Given that BeyondTrust products are commonly used to manage privileged access across enterprise environments, compromise of these appliances poses significant lateral movement risk (GitHub Advisory, BeyondTrust Advisory).
A proof-of-concept write-up has been published by researcher Deniz Halil as of July 10, 2026, providing exploitation details (Deniz Halil PoC). The EPSS score is approximately 0.42%, placing it in the 34th percentile for exploitation probability within 30 days. As of the time of reporting, NVD SSVC data indicates exploitation status as "none" confirmed in the wild, and the vulnerability has not been added to the CISA KEV catalog. No threat actor attribution has been publicly reported. The vulnerability is not automatable due to the required specific authentication configuration precondition (GitHub Advisory).
BeyondTrust has released version 25.3.3 for both Remote Support and Privileged Remote Access, which addresses this vulnerability; organizations should upgrade immediately (BeyondTrust Advisory). As an interim measure where immediate patching is not possible, administrators should review and disable the specific authentication configuration that enables exploitation, implement network segmentation to restrict access to BeyondTrust appliances, and monitor for unauthorized access attempts. Cloud-hosted BeyondTrust instances were patched automatically by the vendor. Prioritize patching self-hosted deployments, as these remain exposed until manually updated (GitHub Advisory, BleepingComputer).
BeyondTrust published security advisory BT26-03 disclosing the vulnerability and providing patching guidance (BeyondTrust Advisory). The Hacker News, BleepingComputer, and multiple cybersecurity news outlets covered the disclosure prominently, noting the critical severity and the risk to enterprise remote access infrastructure (The Hacker News, BleepingComputer). National CERTs including Ireland's NCSC and Singapore's CSA issued advisories urging organizations to patch immediately. Community discussion on Reddit and social media highlighted concern over the privileged access nature of the affected products and the availability of a public PoC write-up.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."