CVE-2026-40140 – BeyondTrust Remote Support
“Authentication is the front door—when it fails, everything behind it is at risk.”
BeyondTrust has released security updates for Remote Support and Privileged Remote Access to address four vulnerabilities affecting authentication, network communication, and web application components. The most critical issues, CVE-2026-40138 and CVE-2026-40139, are pre-authentication authentication bypass vulnerabilities that could allow an attacker to gain unauthorized access to affected appliances, including accounts with elevated privileges, when a specific authentication configuration is enabled. CVE-2026-40140 could allow an unauthenticated attacker to trigger a denial-of-service condition, while CVE-2026-40141 could enable an authenticated user with limited privileges to access resources beyond their intended authorization.
CVE-2026-40138 has a CVSS score of 9.2, which is Critical severity. CVE-2026-40139 has a CVSS score of 9.2, which is Critical severity. CVE-2026-40140 has a CVSS score of 8.7, which is High severity. CVE-2026-40141 has a CVSS score of 8.5, which is High severity. Based on the information provided, there is no verified exploitation associated with these vulnerabilities. Organizations using the affected products should apply the available updates to mitigate the authentication and access control risks.
Key Details
- Affected Product
- Beyondtrust Privileged Remote Access
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- CWE Classification
- CWE-400