High severity8.1NVD Advisory· Published Jul 6, 2026· Updated Jul 7, 2026
CVE-2026-40138
CVE-2026-40138
Description
A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support and Privileged Remote Access. Improper validation of authentication data may allow a network-positioned attacker to bypass access controls and gain unauthorized access to the appliance, including accounts with elevated privileges. Exploitation requires a specific authentication configuration to be enabled
Affected products
4- cpe:2.3:a:beyondtrust:privileged_remote_access:*:*:*:*:*:*:*:*Range: <25.3.3
cpe:2.3:a:beyondtrust:remote_support:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:beyondtrust:remote_support:*:*:*:*:*:*:*:*range: <25.3.3
- (no CPE)
Patches
Vulnerability mechanics
References
1- www.beyondtrust.com/trust-center/security-advisories/bt26-03nvdVendor Advisory
News mentions
0No linked articles in our index yet.