CVE-2026-40140
BeyondTrust Privileged Remote Access Client vulnerability analysis and mitigation

Overview

CVE-2026-40140 is a pre-authentication denial-of-service vulnerability in BeyondTrust Remote Support and Privileged Remote Access, located in the network communication subsystem. Insufficient validation of client-supplied input allows an unauthenticated remote attacker to trigger a denial-of-service condition affecting appliance availability. Affected versions are Remote Support and Privileged Remote Access up to and including 25.3.2 (fixed in 25.3.3); some sources also reference a fix in 26.2.1 for certain product lines. It was published on July 6, 2026, with a CVSS v3.1 score of 7.5 (High) and a CVSS v4.0 score of 8.7 (High) (GitHub Advisory, BeyondTrust Advisory).

Technical details

The vulnerability is classified as CWE-400 (Uncontrolled Resource Consumption), meaning the affected network communication subsystem fails to properly control the allocation or maintenance of resources when processing client-supplied input. An unauthenticated attacker can send specially crafted network requests to the appliance, causing resource exhaustion or a crash that disrupts service availability. No authentication or user interaction is required, and the attack can be launched remotely over the network with low complexity. Attack patterns associated with this vulnerability include XML Ping of the Death (CAPEC-147) and Regular Expression Exponential Blowup (CAPEC-492), suggesting the flaw may involve malformed or resource-intensive input parsing (GitHub Advisory, BeyondTrust Advisory).

Impact

Successful exploitation results in a denial-of-service condition that disrupts the availability of BeyondTrust Remote Support and Privileged Remote Access appliances. There is no impact to confidentiality or integrity — the vulnerability is limited to availability. Because BeyondTrust Remote Support and Privileged Remote Access are enterprise remote access platforms often used for privileged session management, an outage could prevent administrators and support staff from accessing critical systems, potentially impacting business continuity and incident response capabilities (GitHub Advisory, BeyondTrust Advisory).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The NVD SSVC assessment classifies the vulnerability as automatable with no known exploitation. The EPSS score is approximately 0.56% (43rd percentile), indicating a relatively low but non-negligible probability of exploitation within 30 days. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.

Exploitation steps

  1. Reconnaissance: Identify internet-facing BeyondTrust Remote Support or Privileged Remote Access appliances running versions 25.3.2 or earlier using tools such as Shodan or Censys, searching for BeyondTrust-specific service banners or known ports.
  2. Craft malicious input: Prepare a specially crafted network request targeting the appliance's network communication subsystem — potentially involving malformed XML, oversized payloads, or regex-triggering patterns consistent with CAPEC-147 or CAPEC-492 attack patterns.
  3. Send unauthenticated request: Transmit the crafted request to the appliance without any authentication credentials, exploiting the insufficient input validation in the network subsystem.
  4. Trigger denial-of-service: The appliance fails to properly control resource consumption, leading to resource exhaustion or a crash that renders the appliance unavailable to legitimate users (GitHub Advisory, BeyondTrust Advisory).

Indicators of compromise

  • Network: Unusual volume of unauthenticated requests to BeyondTrust appliance network ports from external or unexpected IP addresses; repeated connection attempts with malformed or oversized payloads.
  • Logs: Appliance logs showing repeated errors or exceptions in the network communication subsystem; resource exhaustion warnings or crash/restart events in system logs around the time of the incident.
  • Availability: Unexpected appliance unresponsiveness or service restarts; monitoring alerts for BeyondTrust service downtime or failed health checks.

Mitigation and workarounds

BeyondTrust has released patched versions 25.3.3 (and 26.2.1 for certain product lines) for both Remote Support and Privileged Remote Access; upgrading to these versions is the primary recommended remediation (BeyondTrust Advisory). As a network-based workaround, organizations should implement network-level access controls (firewalls, allowlists) to restrict connectivity to BeyondTrust appliances to trusted networks and IP ranges only. Additionally, monitor appliance availability and configure alerting for unexpected service disruptions to enable rapid detection and response.

Community reactions

The vulnerability received broad coverage from security media outlets including BleepingComputer, The Hacker News, SC World, and CybersecurityNews, often grouped with related BeyondTrust CVEs (CVE-2026-40138, CVE-2026-40139) disclosed in the same advisory (BleepingComputer, The Hacker News). National CERTs including Singapore's CSA and Thailand's ThaiCERT issued advisories urging organizations to patch promptly. Community discussion on Mastodon and Bluesky noted the significance of pre-authentication vulnerabilities in privileged access management tools given BeyondTrust's history of high-profile exploitation in 2024–2025.

Additional resources


SourceThis report was generated using AI

Related BeyondTrust Privileged Remote Access Client vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-1731CRITICAL9.9
  • BeyondTrust Privileged Remote Access Client logoBeyondTrust Privileged Remote Access Client
  • cpe:2.3:a:beyondtrust:privileged_remote_access
YesYesFeb 06, 2026
CVE-2026-40139CRITICAL9.2
  • BeyondTrust Privileged Remote Access Client logoBeyondTrust Privileged Remote Access Client
  • cpe:2.3:a:beyondtrust:privileged_remote_access
NoYesJul 06, 2026
CVE-2026-40138CRITICAL9.2
  • BeyondTrust Privileged Remote Access Client logoBeyondTrust Privileged Remote Access Client
  • cpe:2.3:a:beyondtrust:privileged_remote_access
NoYesJul 06, 2026
CVE-2026-40140HIGH8.7
  • BeyondTrust Privileged Remote Access Client logoBeyondTrust Privileged Remote Access Client
  • cpe:2.3:a:beyondtrust:privileged_remote_access
NoYesJul 06, 2026
CVE-2026-40141HIGH8.5
  • BeyondTrust Privileged Remote Access Client logoBeyondTrust Privileged Remote Access Client
  • cpe:2.3:a:beyondtrust:privileged_remote_access
NoYesJul 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management