
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-40139 is a critical pre-authentication authentication bypass vulnerability in the authentication subsystem of BeyondTrust Remote Support and Privileged Remote Access (PRA). Improper processing of authentication requests may allow an unauthenticated remote attacker to bypass access controls and gain unauthorized access to the appliance, including accounts with elevated privileges. Exploitation requires a specific authentication configuration to be enabled on the affected appliance. Both products are affected in versions up to and including 25.3.2 (fixed in 25.3.3), with cloud-hosted instances patched earlier. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical) and a CVSS v4.0 base score of 9.2 (Critical) (GitHub Advisory, BeyondTrust Advisory).
The vulnerability is classified as CWE-287 (Improper Authentication), meaning the product fails to adequately verify that an actor's claimed identity is legitimate during the authentication process (GitHub Advisory). The flaw resides in the authentication subsystem of BeyondTrust Remote Support and PRA, where improper processing of authentication requests enables an unauthenticated remote attacker to bypass access controls entirely over the network without requiring any privileges or user interaction. A key precondition is that a specific authentication configuration must be enabled on the appliance — the exact configuration is not publicly disclosed by BeyondTrust, limiting opportunistic exploitation. No public proof-of-concept code has been identified as of the time of reporting (BeyondTrust Advisory).
Successful exploitation allows an unauthenticated remote attacker to gain unauthorized access to the BeyondTrust Remote Support or PRA appliance, including accounts with elevated privileges. This results in high impact to confidentiality, integrity, and availability of the vulnerable system, potentially enabling full administrative control over the remote access platform. Because BeyondTrust Remote Support and PRA are widely used in enterprise environments to manage privileged access to critical infrastructure, a compromise could facilitate lateral movement, credential harvesting, and access to downstream systems managed through the platform (GitHub Advisory, BeyondTrust Advisory).
As of the time of reporting, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation (GitHub Advisory). The EPSS score is approximately 0.65% (47th percentile), indicating a moderate but not elevated near-term exploitation probability. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The CVSS v4.0 metric notes that attack requirements are "Present," meaning a specific configuration must be active, which somewhat limits the attack surface compared to a fully unconditional bypass. No threat actor attribution has been reported at this time.
BeyondTrust has released version 25.3.3 for both Remote Support and Privileged Remote Access, which addresses this vulnerability; organizations should upgrade immediately (BeyondTrust Advisory). Cloud-hosted BeyondTrust instances were patched earlier (by version 26.2.1 per ENISA data). As a workaround, administrators should review and restrict the specific authentication configuration that enables exploitation — disabling non-essential authentication methods reduces exposure. Additionally, implementing network access controls to limit appliance access to trusted IP ranges and monitoring for anomalous authentication activity are recommended interim measures (GitHub Advisory).
The vulnerability received broad coverage from security media outlets including BleepingComputer, The Hacker News, and CybersecurityNews, with multiple articles highlighting the critical severity and the risk to enterprise remote access infrastructure (BleepingComputer, The Hacker News). The SANS Internet Storm Center discussed the vulnerability in a podcast episode, and national CERTs including Ireland's NCSC and Singapore's CSA issued advisories urging prompt patching. Community discussion on Reddit and social platforms (Bluesky, Mastodon) noted the significance given BeyondTrust's prior high-profile exploitation history (e.g., CVE-2024-12356). Beazley Security Labs published an independent advisory (BSL-A1186), and SOCRadar and CyCognito produced threat intelligence analyses covering the vulnerability alongside the related CVE-2026-40138.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."