BeyondTrust fixes critical pre-auth bug allowing remote code execution

3 Min Read

BeyondTrust patched a critical pre-auth flaw in Remote Support and PRA that could let attackers execute code remotely.

BeyondTrust released security updates to address a critical flaw, tracked as CVE-2026-1731 (CVSS score of 9.9), in its Remote Support and older Privileged Remote Access products. The bug could allow an unauthenticated attacker to send specially crafted requests and run operating system commands remotely, without logging in. The issue, disclosed on February 6, 2026, could lead to full remote code execution if exploited, making the updates essential to prevent abuse.

- Advertisement -

“BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability.” reads the advisory. “By sending specially crafted requests, an unauthenticated remote attacker may be able to execute operating system commands in the context of the site user.”

Exploiting the flaw would let a remote attacker run system commands without authentication or user interaction, potentially leading to full system compromise, data theft, and service disruption.


What do you think? Post a comment.


” Successful exploitation could allow an unauthenticated remote attacker to execute operating system commands in the context of the site user.” continues the advisory. “Successful exploitation requires no authentication or user interaction and may lead to system compromise, including unauthorized access, data exfiltration, and service disruption.”

- Advertisement -

EXPLORE MORE

Microsoft alerts on DNS-based ClickFix variant delivering malware via nslookup

Microsoft warns of a new ClickFix variant that tricks users into running…

Falklands Emerge As US Leverage Tool Against Britain To Ramp Defense Spending

A new report from The Telegraph says the Trump administration is using…

Berlin built a wall around the AfD. Voters just smashed it

On the night of September 7, 2026, the results of landmark state…

ApolloMD data breach impacts 626,540 people

A May 2025 cyberattack on ApolloMD exposed the personal data of over…

“A Hail Mary Pass”: John Mearsheimer on Trump’s Iranian Economic Strategy and Strategic Defeat

WASHINGTON — In the wake of Treasury Secretary Scott Bessent’s announcement of…

Fintech firm Figure disclosed data breach after employee phishing attack

Fintech firm Figure confirmed a data breach after hackers used social engineering…

The vulnerability impacts:

  • Remote Support versions 25.3.1 and prior
  • Privileged Remote Access versions 24.3.4 and prior

Below are the fixed software versions:

Product Version
Remote Support Patch BT26-02-RS
25.3.2 and later
Privileged Remote Access Patch BT26-02-PRA
25.1.1 and later

Harsh Jaiswal and the Hacktron AI team reported the vulnerability.

SaaS customers were automatically protected, as the fix was deployed to all Remote Support and Privileged Remote Access cloud environments on February 2, 2026.

For self-hosted deployments, administrators must manually install the patch if automatic updates are not enabled. Systems running older versions must first upgrade to a supported release before applying the fix. In particular, PRA self-hosted customers can resolve the flaw by upgrading to version 25.1.1 or later.

Hacktron AI team reported that roughly 11,000 BeyondTrust Remote Support instances are exposed online across cloud and on-prem environments. Around 8,500 of these are on-prem systems and could remain vulnerable if not patched. The affected deployments are mainly used by large organizations, including enterprises in healthcare, financial services, government, and hospitality sectors.

“At this time, we are withholding technical details to allow affected parties sufficient time to apply patches. We strongly recommend addressing this vulnerability promptly, as exploitation is straightforward.” wrote Hacktron.

Pierluigi Paganini



Share This Article

US Steps Up Africa Push As China Expands Economic, Security Footprint

Authored by Arthur Zhang via The Epoch Times, The…

CIA Director Pushed Trump-Putin-Zelensky Summit During Moscow Visit: Report

Yet another take has been issued, and more alleged…

Key Democratic Senate Candidate’s Campaign Descends Into ‘Complete Chaos’

Just hours before a key jungle primary decided the…

The Songwriter Who Taught America How to Love: Remembering Dolly Parton

There are rare figures in American culture who do…

US-Backed SDF Leader Joins Sharaa Regime As Presidential Advisor After Kurdish Force Dissolved

Via The Cradle Self-proclaimed Syrian President Ahmad al-Sharaa has…

Deposition of Renowned Vaccinologist Dr. Stanley Plotkin Sparks Debate Over Historical Research Ethics

A nine-hour legal deposition featuring Dr. Stanley Plotkin—widely regarded…

Cops Raid Home of Rep. Ilhan Omar’s Son, Seizing Firearms and Ammunition

MINNEAPOLIS — Police executed a search warrant at a…

CONVERSATION

Subscribe
Notify of
guest
0 Comments
Oldest
Newest Most Voted