
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-40141 is a high-severity authorization bypass vulnerability in BeyondTrust Remote Support and Privileged Remote Access (PRA) caused by insufficient validation of user-supplied input parameters in a web application component. It affects all versions of both products up to and including 25.3.2 (fixed in 25.3.3). The vulnerability was published on July 6, 2026, with a patch released the same day. It carries a CVSS v3.1 base score of 9.9 (Critical) and a CVSS v4.0 base score of 8.5 (High) (GitHub Advisory, BeyondTrust Advisory).
The root cause is classified as CWE-943 (Improper Neutralization of Special Elements in Data Query Logic), which maps to CAPEC-676 (NoSQL Injection), indicating that the vulnerability likely involves manipulation of query logic through crafted input parameters in the web application layer (GitHub Advisory). An authenticated attacker with limited, specific permissions can supply specially crafted input to a vulnerable web component, causing the application to process queries or access resources outside the attacker's authorized scope. Exploitation requires network access and a valid low-privilege account with specific permissions, but no user interaction or elevated complexity is needed (BeyondTrust Advisory).
Successful exploitation allows an authenticated attacker with limited privileges to access unintended resources and data beyond their authorization scope, resulting in high confidentiality impact on both the vulnerable and subsequent systems. The CVSS v4.0 scoring also reflects high integrity and availability impact on subsequent systems, suggesting the vulnerability could be leveraged to affect connected infrastructure or managed endpoints. Given that BeyondTrust Remote Support and PRA are privileged access management tools used in enterprise environments, unauthorized access could expose sensitive credentials, session data, or managed systems, with significant potential for lateral movement (GitHub Advisory, BeyondTrust Advisory).
As of the time of reporting, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The NVD SSVC assessment rates exploitation as "none" and the vulnerability as not automatable. The EPSS score is approximately 0.41–0.48%, placing it in the 38th percentile for exploitation likelihood within 30 days. No threat actor attribution has been reported, and the vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
BeyondTrust released a patch on July 6, 2026; organizations should upgrade both Remote Support and Privileged Remote Access to version 25.3.3 or later (BeyondTrust Advisory). As interim measures, administrators should review and restrict user permissions to the minimum necessary for job functions, and monitor access logs for unauthorized resource access attempts. Implementing additional input validation and authorization checks at the application layer can further reduce risk until patching is complete.
The vulnerability received broad coverage from security media outlets including BleepingComputer, The Hacker News, GBHackers, and CyberSecurityNews, with many articles framing it alongside related BeyondTrust flaws (notably CVE-2026-40138) as a cluster of critical authentication and authorization bypass issues (BleepingComputer, The Hacker News). Government CERTs including Singapore's CSA and Thailand's ThaiCERT issued advisories urging prompt patching. The H-ISAC also published a TLP:WHITE vulnerability bulletin for the healthcare sector. Community sentiment reflects urgency given BeyondTrust's history of high-profile exploitation (e.g., the 2024 BeyondTrust breach), though no active exploitation of this specific CVE has been observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."