Cyber Security News

Critical BeyondTrust Flaws Let Attackers Bypass Access Controls and Gain Unauthorized Access

BeyondTrust has disclosed multiple critical and high-severity vulnerabilities affecting its Remote Support (RS) and Privileged Remote Access (PRA) solutions, potentially allowing attackers to bypass access controls and gain unauthorized access to sensitive systems.

The issues are tracked under Advisory ID BT26-03 and carry a maximum CVSS v4 score of 9.2, indicating a severe risk to impacted environments.

According to the advisory, the vulnerabilities were discovered internally by BeyondTrust’s Product Security team as part of its ongoing security research efforts.

The company also noted that its findings were supported by AI-driven vulnerability discovery techniques, using both publicly available models and proprietary tools.

BeyondTrust Vulnerabilities

The research was conducted independently and is not related to external projects. The most critical flaws, CVE-2026-40138 and CVE-2026-40139, stem from improper authentication mechanisms in the affected products.

These pre-authentication vulnerabilities could allow unauthenticated attackers to bypass access controls under certain configurations.

Successful exploitation may grant attackers unauthorized access to the appliance, including accounts with elevated privileges, significantly increasing the risk of compromise.

CVE-2026-40138 affects both Remote Support and Privileged Remote Access and involves improper validation of authentication data. CVE-2026-40139 specifically impacts Remote Support and is caused by improper processing of authentication requests.

In both cases, exploitation depends on specific authentication configurations being enabled. However, no user interaction is required, making them particularly dangerous in exposed environments.

In addition to the critical flaws, two high-severity vulnerabilities were also identified. CVE-2026-40140 is a pre-authentication issue in the network communication subsystem that could allow attackers to trigger a denial-of-service condition, potentially disrupting service availability.

Meanwhile, CVE-2026-40141 affects a web application component. It could allow authenticated users with limited privileges to access unintended resources due to improper input validation.

BeyondTrust confirmed that cloud-hosted customers were automatically patched as of April 21, 2026. However, organizations using self-hosted deployments remain at risk if updates have not been applied. The vulnerabilities affect Remote Support and PRA versions 25.3.2 and earlier.

To mitigate the risk, customers are advised to apply the April 2026 security rollup patches or upgrade to version 25.3.3 or later for both RS and PRA. These updates address all known vulnerabilities outlined in the advisory.

Security teams should prioritize patching, especially in environments where remote access tools are exposed to external networks.

Given the potential for unauthenticated exploitation and privilege escalation, these flaws could be leveraged in targeted attacks or broader intrusion campaigns if left unaddressed.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

CISA Red Team Breaches Critical Infrastructure to Reveal SOC and Cloud Security Gaps

CISA's latest advisory for red teams warns critical infrastructure operators that security systems can fail…

3 hours ago

AI Security Startup Alice Raises $140 Million as Enterprise AI Threats Surge

Alice, the AI trust, safety, and security company formerly known as ActiveFence, has closed a…

4 hours ago

SynkLoader Mimic as IT Support Personnel Attacking Users Via Microsoft Teams

SynkLoader is using Microsoft Teams conversations to turn routine IT support requests into a route…

5 hours ago

ToxNetV2 Linux Botnet Uses NVIDIA AI to Generate Shell and Remote SSH Attack Actions

ToxNetV2 is a Linux botnet that shows how artificial intelligence can move closer to real…

5 hours ago

WhatsApp Passkeys Reach 1 Billion Users as Two-Step Verification Gets Stronger Passwords

WhatsApp has confirmed that more than 1 billion people now use passkeys to log into…

6 hours ago

ASOS Warns Customer Accounts Were Accessed Using Compromised Login Credentials

ASOS US Sales LLC reported unauthorized access to customer accounts using credentials obtained from outside…

6 hours ago