CVE-2026-40140 – BeyondTrust Remote Support

CVSS 7.5 IMPORTANT Critical - Same Day Deployment

“Authentication is the front door—when it fails, everything behind it is at risk.”

BeyondTrust has released security updates for Remote Support and Privileged Remote Access to address four vulnerabilities affecting authentication, network communication, and web application components. The most critical issues, CVE-2026-40138 and CVE-2026-40139, are pre-authentication authentication bypass vulnerabilities that could allow an attacker to gain unauthorized access to affected appliances, including accounts with elevated privileges, when a specific authentication configuration is enabled. CVE-2026-40140 could allow an unauthenticated attacker to trigger a denial-of-service condition, while CVE-2026-40141 could enable an authenticated user with limited privileges to access resources beyond their intended authorization.

CVE-2026-40138 has a CVSS score of 9.2, which is Critical severity. CVE-2026-40139 has a CVSS score of 9.2, which is Critical severity. CVE-2026-40140 has a CVSS score of 8.7, which is High severity. CVE-2026-40141 has a CVSS score of 8.5, which is High severity. Based on the information provided, there is no verified exploitation associated with these vulnerabilities. Organizations using the affected products should apply the available updates to mitigate the authentication and access control risks.

Key Details

Affected Product
Beyondtrust Privileged Remote Access
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-400
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.