CVE-2026-40139
BeyondTrust Privileged Remote Access Client vulnerability analysis and mitigation

Overview

CVE-2026-40139 is a critical pre-authentication authentication bypass vulnerability in the authentication subsystem of BeyondTrust Remote Support and Privileged Remote Access (PRA). Improper processing of authentication requests may allow an unauthenticated remote attacker to bypass access controls and gain unauthorized access to the appliance, including accounts with elevated privileges. Exploitation requires a specific authentication configuration to be enabled on the affected appliance. Both products are affected in versions up to and including 25.3.2 (fixed in 25.3.3), with cloud-hosted instances patched earlier. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical) and a CVSS v4.0 base score of 9.2 (Critical) (GitHub Advisory, BeyondTrust Advisory).

Technical details

The vulnerability is classified as CWE-287 (Improper Authentication), meaning the product fails to adequately verify that an actor's claimed identity is legitimate during the authentication process (GitHub Advisory). The flaw resides in the authentication subsystem of BeyondTrust Remote Support and PRA, where improper processing of authentication requests enables an unauthenticated remote attacker to bypass access controls entirely over the network without requiring any privileges or user interaction. A key precondition is that a specific authentication configuration must be enabled on the appliance — the exact configuration is not publicly disclosed by BeyondTrust, limiting opportunistic exploitation. No public proof-of-concept code has been identified as of the time of reporting (BeyondTrust Advisory).

Impact

Successful exploitation allows an unauthenticated remote attacker to gain unauthorized access to the BeyondTrust Remote Support or PRA appliance, including accounts with elevated privileges. This results in high impact to confidentiality, integrity, and availability of the vulnerable system, potentially enabling full administrative control over the remote access platform. Because BeyondTrust Remote Support and PRA are widely used in enterprise environments to manage privileged access to critical infrastructure, a compromise could facilitate lateral movement, credential harvesting, and access to downstream systems managed through the platform (GitHub Advisory, BeyondTrust Advisory).

Exploitability

As of the time of reporting, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation (GitHub Advisory). The EPSS score is approximately 0.65% (47th percentile), indicating a moderate but not elevated near-term exploitation probability. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The CVSS v4.0 metric notes that attack requirements are "Present," meaning a specific configuration must be active, which somewhat limits the attack surface compared to a fully unconditional bypass. No threat actor attribution has been reported at this time.

Exploitation steps

  1. Reconnaissance: Identify internet-facing BeyondTrust Remote Support or Privileged Remote Access appliances running versions 25.3.2 or earlier using tools such as Shodan or Censys, searching for BeyondTrust-specific banners or login pages.
  2. Identify authentication configuration: Determine whether the target appliance has the specific authentication configuration enabled that is required for exploitation (the exact configuration is not publicly disclosed; attackers may probe for non-standard authentication endpoints or methods).
  3. Craft malicious authentication request: Send a specially crafted authentication request to the appliance's authentication subsystem that exploits the improper processing logic, bypassing normal credential validation.
  4. Bypass access controls: The improper authentication handling allows the attacker to authenticate without valid credentials, gaining access to the appliance including elevated privilege accounts.
  5. Post-exploitation: With privileged access to the BeyondTrust appliance, the attacker can access managed endpoints, harvest credentials, establish persistence, or pivot laterally to systems managed through the remote support platform (GitHub Advisory, BeyondTrust Advisory).

Indicators of compromise

  • Network: Unexpected or anomalous authentication requests to the BeyondTrust Remote Support or PRA appliance from unknown or untrusted IP addresses; successful authentication events originating from external or unusual sources without corresponding legitimate user activity.
  • Logs: Authentication success events in appliance logs for privileged accounts with no corresponding MFA or expected credential usage; login events at unusual times or from unexpected geographic locations; absence of expected authentication steps (e.g., missing password validation log entries).
  • Process/Session: Unexpected administrative sessions or configuration changes on the BeyondTrust appliance; new user accounts or privilege escalations performed shortly after anomalous authentication events.
  • File System: Unexpected changes to appliance configuration files or authentication settings; new scheduled tasks or scripts added to the appliance system.

Mitigation and workarounds

BeyondTrust has released version 25.3.3 for both Remote Support and Privileged Remote Access, which addresses this vulnerability; organizations should upgrade immediately (BeyondTrust Advisory). Cloud-hosted BeyondTrust instances were patched earlier (by version 26.2.1 per ENISA data). As a workaround, administrators should review and restrict the specific authentication configuration that enables exploitation — disabling non-essential authentication methods reduces exposure. Additionally, implementing network access controls to limit appliance access to trusted IP ranges and monitoring for anomalous authentication activity are recommended interim measures (GitHub Advisory).

Community reactions

The vulnerability received broad coverage from security media outlets including BleepingComputer, The Hacker News, and CybersecurityNews, with multiple articles highlighting the critical severity and the risk to enterprise remote access infrastructure (BleepingComputer, The Hacker News). The SANS Internet Storm Center discussed the vulnerability in a podcast episode, and national CERTs including Ireland's NCSC and Singapore's CSA issued advisories urging prompt patching. Community discussion on Reddit and social platforms (Bluesky, Mastodon) noted the significance given BeyondTrust's prior high-profile exploitation history (e.g., CVE-2024-12356). Beazley Security Labs published an independent advisory (BSL-A1186), and SOCRadar and CyCognito produced threat intelligence analyses covering the vulnerability alongside the related CVE-2026-40138.

Additional resources


SourceThis report was generated using AI

Related BeyondTrust Privileged Remote Access Client vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-1731CRITICAL9.9
  • BeyondTrust Privileged Remote Access Client logoBeyondTrust Privileged Remote Access Client
  • cpe:2.3:a:beyondtrust:privileged_remote_access
YesYesFeb 06, 2026
CVE-2026-40139CRITICAL9.2
  • BeyondTrust Privileged Remote Access Client logoBeyondTrust Privileged Remote Access Client
  • cpe:2.3:a:beyondtrust:privileged_remote_access
NoYesJul 06, 2026
CVE-2026-40138CRITICAL9.2
  • BeyondTrust Privileged Remote Access Client logoBeyondTrust Privileged Remote Access Client
  • cpe:2.3:a:beyondtrust:privileged_remote_access
NoYesJul 06, 2026
CVE-2026-40140HIGH8.7
  • BeyondTrust Privileged Remote Access Client logoBeyondTrust Privileged Remote Access Client
  • cpe:2.3:a:beyondtrust:privileged_remote_access
NoYesJul 06, 2026
CVE-2026-40141HIGH8.5
  • BeyondTrust Privileged Remote Access Client logoBeyondTrust Privileged Remote Access Client
  • cpe:2.3:a:beyondtrust:privileged_remote_access
NoYesJul 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management