VDB
CVE-2026-40139
CVE-2026-40139
PUBLISHED
CVSS 9.2 CRITICAL
Reported by BT · Published July 6, 2026
A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. Improper processing of authentication requests may allow an unauthenticated remote attacker to bypass access controls and gain unauthorized access to the appliance, including accounts with elevated privileges. Exploitation requires a specific authentication configuration to be enabled.
Risk Scores
CVSS 4.0
9.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| BeyondTrust | Remote Support | 0 |
| BeyondTrust | Privileged Remote Access | 0 |
| BeyondTrust | Privileged Remote Access | 0, 0, 0 |
| BeyondTrust | Remote Support | 0, 0, 0 |
Timeline
- Jul 6, 2026 CVE Published
- Jul 7, 2026 EPSS Score
- Jul 7, 2026 Coalition ESS Score
- Jul 7, 2026 CVE Updated