CVE-2026-40138: BeyondTrust Pre-Authentication Bypass (Remote Support & Privileged Remote Access)
BeyondTrust Remote Support and Privileged Remote Access contain a critical flaw in how they validate authentication credentials before a user logs in. An attacker on the network can exploit this weakness to bypass normal login protections and gain unauthorized access to the appliance, potentially including high-privilege accounts. The vulnerability only affects systems where a specific authentication configuration is enabled, which limits but does not eliminate the risk footprint.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 8.1 HIGH · CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Weaknesses (CWE)
- CWE-287
- Affected products
- 2 configuration(s)
- Published / Modified
- 2026-07-06 / 2026-07-07
NVD description (verbatim)
A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support and Privileged Remote Access. Improper validation of authentication data may allow a network-positioned attacker to bypass access controls and gain unauthorized access to the appliance, including accounts with elevated privileges. Exploitation requires a specific authentication configuration to be enabled
1 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-40138 is a pre-authentication authentication bypass vulnerability (CWE-287) affecting the authentication subsystem of BeyondTrust Remote Support and Privileged Remote Access. The vulnerability stems from improper validation of authentication data, allowing network-positioned attackers to circumvent access controls without valid credentials. The CVSS 3.1 score of 8.1 (HIGH) reflects high confidentiality, integrity, and authenticity impact with a network attack vector and high attack complexity, indicating the vulnerability is difficult but not impossible to exploit. A specific authentication configuration must be enabled for exploitation to succeed.
Business impact
Successful exploitation could result in complete compromise of the appliance, including unauthorized access to sensitive administrative functions and elevated-privilege accounts. Organizations using BeyondTrust for remote support or privileged access management face potential data exposure, lateral movement opportunities within managed infrastructure, and loss of control over privileged sessions. The reputational and operational impact is significant, as these products are often trusted for secure remote access to critical systems.
Affected systems
BeyondTrust Remote Support and BeyondTrust Privileged Remote Access are affected. The vulnerability is triggered only when a specific authentication configuration is enabled, so organizations should audit their deployment settings to determine exposure. Verify the exact affected versions and patch releases against BeyondTrust's official security advisory.
Exploitability
The vulnerability requires network access and a specific authentication configuration to be active, which raises the attack complexity to HIGH. However, no user interaction is required, and the attacker needs no pre-existing credentials. The barrier to exploitation is meaningful but not prohibitive for an attacker with network positioning and knowledge of the target environment. The vulnerability has not been added to the KEV catalog, indicating no known active exploitation in the wild at the time of publication.
Remediation
Apply patches from BeyondTrust for both Remote Support and Privileged Remote Access immediately upon availability. Verify the specific patched versions in BeyondTrust's security advisory. As an interim measure, review and restrict the authentication configuration settings mentioned in the vulnerability description to disable the affected configuration if operationally feasible, and implement network segmentation to limit access to the appliance from untrusted networks.
Patch guidance
Contact BeyondTrust support or monitor their security advisories for patched versions of Remote Support and Privileged Remote Access. Apply patches during a maintenance window after thorough testing in a non-production environment. Prioritize appliances exposed to untrusted networks or internet-facing deployments. Verify patch deployment and validate that the vulnerable authentication configuration is no longer exploitable post-patching.
Detection guidance
Monitor network traffic to BeyondTrust appliances for anomalous authentication attempts, especially patterns that bypass normal login workflows or succeed without valid credentials. Review appliance logs for failed authentication events followed by successful access with elevated privileges, or direct privilege escalation without a preceding successful authentication. Implement alerts for any authentication bypass indicators specific to the affected configuration setting. Consult BeyondTrust's detection guidance for indicators of compromise.
Why prioritize this
Although the CVSS score is 8.1 (HIGH) rather than CRITICAL, this vulnerability merits urgent attention because it is pre-authentication, allows direct access to sensitive privileged access management infrastructure, and affects both Remote Support and Privileged Remote Access products which are pervasive in enterprise environments. The high attack complexity and specific configuration requirement provide some tactical breathing room, but the lack of exploitation requirements (no user interaction, no pre-existing credentials) and the severity of potential impact make rapid patching essential for organizations running these products.
Risk score, explained
The CVSS 3.1 score of 8.1 reflects a pre-authentication attack with network access (AV:N), high attack complexity due to the required specific configuration (AC:H), no privilege or user interaction requirements (PR:N/UI:N), and complete compromise of confidentiality, integrity, and authenticity (C:H/I:H/A:H). The unchanged scope (S:U) indicates the impact is limited to the vulnerable component. The HIGH severity is justified by the combination of pre-authentication access, potential privilege escalation, and the critical role of these products in enterprise access management.
Frequently asked questions
Does this vulnerability affect all BeyondTrust Remote Support and Privileged Remote Access deployments?
No. Exploitation requires a specific authentication configuration to be enabled. Organizations should review their BeyondTrust configuration settings to determine whether the vulnerable configuration is active in their environment. Check BeyondTrust's advisory for specifics on which configuration triggers the vulnerability.
Can an attacker exploit this without network access to the appliance?
No. The vulnerability requires network-level access to the BeyondTrust appliance. However, this is a pre-authentication flaw, meaning an attacker does not need valid credentials to attempt exploitation. Organizations should verify that their appliances are not unnecessarily exposed to untrusted networks.
Is this vulnerability currently being exploited in the wild?
No. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog, indicating no known active exploitation at the time of publication. However, security researchers may develop proof-of-concept code after disclosure, so timely patching remains critical.
What immediate actions should we take if we cannot patch immediately?
Audit your BeyondTrust appliances to confirm whether the specific vulnerable authentication configuration is enabled. If it is, consider disabling it temporarily if operations permit, or implement network access controls to limit access to the appliance from trusted networks only. Prioritize patching for internet-facing or untrusted-network-facing instances. Monitor appliance logs for suspicious authentication activity.
This analysis is provided for informational purposes by SEC.co and is based on the published CVE record as of the publication date. BeyondTrust may release additional technical details, updated patch information, or clarifications after this page was authored. Verify patch version numbers, affected versions, affected configurations, and detailed remediation steps directly from BeyondTrust's official security advisory before making deployment decisions. This content does not constitute professional security advice or a guarantee of vulnerability presence in your environment. Organizations should conduct their own assessment of exposure and risk based on their specific configurations, network architecture, and threat landscape. Do not rely solely on this summary for patch prioritization or incident response planning. Source: NVD (public-domain), retrieved 2026-08-15. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2026-10157HIGHOpen5GS NGAP Authentication Bypass Vulnerability – 5G Core Network Risk
- CVE-2026-10167HIGHAuthentication Bypass in BrinaryBrains School Management System
- CVE-2026-10243HIGHSmart Parking System 1.0 Authentication Bypass – Remote Admin Access
- CVE-2026-10281HIGHEnderfga claw-orchestrator Authentication Bypass – Patch Available
- CVE-2026-10288HIGHHotel Reservation System Admin Authentication Bypass
- CVE-2026-10560HIGHIBM Langflow OSS Missing Authentication in Build Endpoints (CVSS 8.2)
- CVE-2026-10617HIGHGoClaw Webhook Authentication Bypass – Remote Exploitation
- CVE-2026-10619HIGHsayan365 Student-Management-System Remote Authentication Bypass