BeyondTrust has released security updates to address multiple critical vulnerabilities in its Remote Support (RS) and Privileged Remote Access (PRA) products. The most severe flaws could allow unauthenticated attackers to bypass access controls and gain unauthorized access to affected appliances.
The vulnerabilities include:
- CVE-2026-40138 (CVSS 9.2): A pre-authentication vulnerability in the authentication subsystem of RS and PRA due to improper validation of authentication data, potentially allowing network-positioned attackers to bypass access controls and gain elevated privileges.
- CVE-2026-40139 (CVSS 9.2): A similar pre-authentication flaw in RS alone, stemming from improper processing of authentication requests, enabling unauthenticated remote attackers to bypass access controls.
- CVE-2026-40140 (CVSS 8.7): A pre-authentication vulnerability in the network communication subsystem due to insufficient input validation, allowing unauthenticated remote attackers to cause a denial-of-service condition.
- CVE-2026-40141 (CVSS 8.5): A vulnerability in a web application component of RS and PRA due to insufficient input validation, allowing authenticated attackers with limited privileges to access unintended resources.
Successful exploitation of CVE-2026-40138 and CVE-2026-40139 requires a specific authentication configuration to be enabled. CVE-2026-40141 exploitation is restricted to accounts with specific permissions. BeyondTrust identified these flaws internally during security assessments, using publicly available AI models like Anthropic Claude Opus 4.8 and proprietary research tooling.
The issues are fixed in RS 25.3.3 and PRA 25.3.3 and above. While no active exploitation has been reported, previous flaws in these products (CVE-2024-12356, CVE-2026-1731) have been exploited to deploy web shells and backdoors, making prompt patching critical.
CVEs: CVE-2026-40138, CVE-2026-40139, CVE-2026-40140, CVE-2026-40141, CVE-2024-12356, CVE-2026-1731, CVE-2026-55200, CVE-2026-46817
Companies: BeyondTrust, Anthropic
Products: BeyondTrust Remote Support, BeyondTrust Privileged Remote Access, Anthropic Claude Opus 4.8
Original source: thehackernews.com