CVE-2026-1731

CRITICAL KEV RANSOMWARE NUCLEI

BeyondTrust RS/PRA - RCE

Title source: llm

Description

BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted requests, an unauthenticated remote attacker may be able to execute operating system commands in the context of the site user.

Exploits (10)

nomisec WORKING POC 14 stars
by win3zz · poc
https://github.com/win3zz/CVE-2026-1731
github WORKING POC 10 stars
by XiaomingX · pythonpoc
https://github.com/XiaomingX/data-cve-poc-py-v1/tree/main/2026/CVE-2026-1731
nomisec WRITEUP 5 stars
by bytehazard · poc
https://github.com/bytehazard/CVE-2026-1731
nomisec SCANNER 4 stars
by cybrdude · poc
https://github.com/cybrdude/cve-2026-1731-scanner
github WORKING POC 1 stars
by jakubie07 · rustremote
https://github.com/jakubie07/CVE-2026-1731
nomisec WORKING POC
by zensheII · remote
https://github.com/zensheII/CVE-2026-1731-PoC
nomisec WORKING POC
by LutfifakeeXone · poc
https://github.com/LutfifakeeXone/CVE-2026-1731
nomisec SCANNER
by hexissam · poc
https://github.com/hexissam/CVE-2026-1731
nomisec SUSPICIOUS
by richardpaimu34 · poc
https://github.com/richardpaimu34/CVE-2026-1731
metasploit WORKING POC EXCELLENT
by Harsh Jaiswal, Jonah Burgess (CryptoCat) · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/beyondtrust_pra_rs_command_injection.rb

Nuclei Templates (1)

BeyondTrust Remote Support - Unauthenticated WebSocket RCE
CRITICALVERIFIEDby attackerkb,hacktron,pdteam
Shodan: http.html:"BeyondTrust"

Scores

CVSS v3 9.8
EPSS 0.8150
EPSS Percentile 99.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2026-02-13
VulnCheck KEV 2026-02-12
ENISA EUVD EUVD-2026-5559
Ransomware Use Confirmed
CWE
CWE-78
Status published
Products (2)
beyondtrust/privileged_remote_access < 25.1
beyondtrust/remote_support < 25.3.2
Published Feb 06, 2026
KEV Added Feb 13, 2026
Tracked Since Feb 18, 2026