← All Advisories

Critical Pre-Authentication Bypass in BeyondTrust Remote Support Allows Unauthorized Access

Last refreshed2026-09-26

Status: UPDATED  |  Advisory ID: CVE-2026-40139

Key Details

CVECVE-2026-40139
CVSS Score / Version9.8 (Critical) / CVSS v3.1
Updated2026-09-24
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsBeyondTrust Remote Support
Classified asCWE-287 (Improper Authentication)
Exploitation prediction (EPSS)0.75% probability of exploitation in the next 30 days (53% percentile) -- FIRST.org's EPSS model.

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
BeyondTrustRemote Support
SubsystemsOT Secure Remote Access/PAM
SectorsMultiple

What to Know

A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. Improper processing of authentication requests may allow an unauthenticated remote attacker to bypass access controls and gain unauthorized access to the appliance, including accounts with elevated privileges. Exploitation requires a specific authentication configuration to be enabled.

What to Do

Monitor BeyondTrust's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-40139
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-40139
Vendor advisoryhttps://www.beyondtrust.com/trust-center/security-advisories/bt26-03