Unrated severityCISA KEVNVD Advisory· Published Feb 6, 2026· Updated Feb 26, 2026
Remote code execution vulnerability in BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)
CVE-2026-1731
Description
BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted requests, an unauthenticated remote attacker may be able to execute operating system commands in the context of the site user.
Affected products
1- BeyondTrust/Remote Support(RS) & Privileged Remote Access(PRA)v5Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
1- Exploits and vulnerabilities in Q1 2026Securelist · May 7, 2026