CVE-2026-1731

9.5 CISA KEV

BeyondTrust · Remote Support (RS) and Privileged Remote Access (PRA)

BeyondTrust Remote Support and Privileged Remote Access are vulnerable to pre-authentication OS command injection, allowing unauthenticated attackers to execute arbitrary system commands.

Executive summary

This critical pre-authentication remote code execution vulnerability in BeyondTrust Remote Support and Privileged Remote Access is currently being actively exploited in the wild.

Vulnerability

The software is susceptible to OS command injection (CWE-78) via specially crafted network requests. This flaw allows an unauthenticated remote attacker to execute arbitrary operating system commands with the privileges of the site user.

Business impact

Successful exploitation of this vulnerability results in full remote code execution, granting an attacker complete control over the affected appliance. Given the nature of these products, which are typically used for administrative access and support, a compromise poses a severe risk of lateral movement, data theft, and unauthorized access to managed infrastructure. The CVSS score of 9.5 reflects the critical severity and the ease with which an unauthenticated attacker can achieve total system compromise.

Remediation

Immediate Action: Apply the vendor-provided patches immediately. For Remote Support (RS), apply patch BT26-02-RS or upgrade to version 25.3.2 or later. For Privileged Remote Access (PRA), apply patch BT26-02-PRA or upgrade to version 25.1.1 or later.

Proactive Monitoring: Review system logs for anomalous outbound network traffic or unexpected process execution initiated by the web service user. Monitor for signs of unauthorized administrative sessions or configuration changes within the BeyondTrust environment.

Compensating Controls: If immediate patching is not feasible, restrict network access to the BeyondTrust management interfaces to trusted IP addresses only. Deploy Web Application Firewall (WAF) rules designed to detect and block malicious command injection patterns targeting the appliance.

Exploitation status

Public Exploit Available: Yes, a Metasploit module exists and multiple public proof-of-concept repositories are available on GitHub.

Analyst recommendation

Due to the confirmed active exploitation and the critical nature of the impact, this vulnerability must be treated as a top priority for remediation. Administrators should perform an immediate inventory of all BeyondTrust appliances and verify that the specified patches are applied. If an appliance is found to be unpatched, assume the environment may already be compromised and initiate incident response procedures accordingly.

More BeyondTrust CVEs

Sources