VDB

CVE-2026-40139

CVE-2026-40139 PUBLISHED CVSS 9.2 CRITICAL

Reported by BT · Published July 6, 2026

A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. Improper processing of authentication requests may allow an unauthenticated remote attacker to bypass access controls and gain unauthorized access to the appliance, including accounts with elevated privileges. Exploitation requires a specific authentication configuration to be enabled.

Risk Scores

CVSS 4.0
9.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Products

VendorProductVersions
BeyondTrustRemote Support0
BeyondTrustPrivileged Remote Access0
BeyondTrustPrivileged Remote Access0, 0, 0
BeyondTrustRemote Support0, 0, 0

Timeline

  • Jul 6, 2026 CVE Published
  • Jul 7, 2026 EPSS Score
  • Jul 7, 2026 Coalition ESS Score
  • Jul 7, 2026 CVE Updated

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›