BeyondTrust, a cybersecurity firm, has recently released updates to address critical security vulnerabilities in their Remote Support (RS) and Privileged Remote Access (PRA) products. These vulnerabilities, if exploited, could allow unauthenticated attackers to gain unauthorized access to susceptible devices, including accounts with elevated privileges. The issues stem from improper validation of authentication data and insufficient validation of client-supplied input, among other factors.
The vulnerabilities are as follows:
- CVE-2026-40138 (CVSS score: 9.2): A pre-authentication vulnerability in the authentication subsystem of BeyondTrust RS and PRA. If successfully exploited, it could allow a network-positioned attacker to bypass access controls and gain unauthorized access to the appliance, including accounts with elevated privileges.
- CVE-2026-40139 (CVSS score: 9.2): Another pre-authentication vulnerability in the authentication subsystem of BeyondTrust RS. This flaw could enable an unauthenticated remote attacker to bypass access controls and gain unauthorized access to the appliance, including accounts with elevated privileges.
- CVE-2026-40140 (CVSS score: 8.7): A pre-authentication vulnerability in the network communication subsystem. An unauthenticated remote attacker could trigger a denial-of-service condition, affecting appliance availability.
- CVE-2026-40141 (CVSS score: 8.5): A vulnerability in the web application component of BeyondTrust RS and PRA. An authenticated attacker with limited privileges could access unintended resources or data beyond their authorization scope.
It's important to note that the successful exploitation of CVE-2026-40138 and CVE-2026-40139 depends on a specific authentication configuration being enabled. Meanwhile, CVE-2026-40141's exploitation is restricted to accounts with specific permissions.
BeyondTrust identified these vulnerabilities through internal security assessments and the use of publicly available AI models, such as Anthropic Claude Opus 4.8, along with their proprietary research tooling. The company emphasizes that the most severe vulnerabilities could allow an unauthenticated remote attacker to bypass access controls and gain unauthorized access to the appliance under specific configurations. Additional vulnerabilities may lead to service disruption, unintended data access, and, under distinct configurations, elevated access by an authenticated user that may impact system integrity.
The issues have been addressed in the following versions:
- Remote Support RS 25.3.2 or lower (Fixed in RS 25.3.3 and above)
- Privileged Remote Access PRA 25.3.2 or lower (Fixed in PRA 25.3.3 and above)
While BeyondTrust hasn't reported any known exploitation of these vulnerabilities in the wild, the company urges users to move quickly to apply the fixes. This is particularly important given the past exploitation of similar vulnerabilities in RS and PRA products (CVE-2024-12356 and CVE-2026-1731) to deploy web shells and backdoors.
As an industry expert, I find these developments concerning. The high CVSS scores of the vulnerabilities highlight the potential severity of the issues. It's crucial for organizations using BeyondTrust RS and PRA to prioritize the application of the fixes to prevent unauthorized access and potential system disruption. The use of AI in identifying vulnerabilities is an interesting development, but it also underscores the need for robust security measures to counter potential threats.