CVE-2026-40141
CRITICALBeyondTrust Remote Support and PRA - Authenticated Unauthorized Data Access
Title source: manualDescription
A high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote Access related to the processing of certain input parameters. Insufficient validation of user-supplied input may allow an authenticated attacker with limited privileges to access unintended resources or data beyond their authorization scope. Exploitation is restricted to accounts with specific permissions.
References (1)
Core 1
Scores
CVSS v3
9.9
EPSS
0.0049
EPSS Percentile
39.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-943
Status
published
Products (8)
BeyondTrust/Privilege Remote Access
< 25.3.2
BeyondTrust/Privilege Remote Access
< 25.3.3
BeyondTrust/Privilege Remote Access
< 26.2.1
beyondtrust/privileged_remote_access
< 25.3.3
BeyondTrust/Remote Support
< 25.3.2
BeyondTrust/Remote Support
< 25.3.3
BeyondTrust/Remote Support
< 26.2.1
beyondtrust/remote_support
< 25.3.3
Published
Jul 06, 2026
Tracked Since
Jul 06, 2026