BeyondTrust patched a critical pre-auth flaw in Remote Support and PRA that could let attackers execute code remotely.
BeyondTrust released security updates to address a critical flaw, tracked as CVE-2026-1731 (CVSS score of 9.9), in its Remote Support and older Privileged Remote Access products. The bug could allow an unauthenticated attacker to send specially crafted requests and run operating system commands remotely, without logging in. The issue, disclosed on February 6, 2026, could lead to full remote code execution if exploited, making the updates essential to prevent abuse.
“BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability.” reads the advisory. “By sending specially crafted requests, an unauthenticated remote attacker may be able to execute operating system commands in the context of the site user.”
Exploiting the flaw would let a remote attacker run system commands without authentication or user interaction, potentially leading to full system compromise, data theft, and service disruption.
” Successful exploitation could allow an unauthenticated remote attacker to execute operating system commands in the context of the site user.” continues the advisory. “Successful exploitation requires no authentication or user interaction and may lead to system compromise, including unauthorized access, data exfiltration, and service disruption.”
EXPLORE MORE
The ‘Russian Bounties’ Hoax: The Fake News Story That Promoted Michael Schwirtz to the Top
In June 2020, The New York Times delivered what appeared to be…
Germany Receives First F-35A as NATO Airpower Grows Amid Rising Threats from Russia
Germany has received its first F-35A stealth fighter from Lockheed Martin as…
Why Samsung Odyssey Ark Dominates As The Best Gaming Monitor Of 2022
Welcome back to the Philly PI hardware desk, where we put the…
High-End Gaming PC Power Consumption: New Utility Plan Lowers Electricity Bills for High-Spec Rigs
German Utility Provider Launches "Gaming Electricity" Plan for High-Consumption Households German utility…
US Army orders 16 new UH-60M Black Hawk helicopters from Sikorsky in $234 million deal
The U.S. Army awarded Lockheed Martin subsidiary Sikorsky a $234.46 million contract…
Star Wars Episode 10 Is Happening: Plot Leaks, Cast Rumors, and What We Know
The galaxy far, far away is once again buzzing with speculation as…
The vulnerability impacts:
- Remote Support versions 25.3.1 and prior
- Privileged Remote Access versions 24.3.4 and prior
Below are the fixed software versions:
| Product | Version |
|---|---|
| Remote Support | Patch BT26-02-RS |
| 25.3.2 and later | |
| Privileged Remote Access | Patch BT26-02-PRA |
| 25.1.1 and later |
Harsh Jaiswal and the Hacktron AI team reported the vulnerability.
SaaS customers were automatically protected, as the fix was deployed to all Remote Support and Privileged Remote Access cloud environments on February 2, 2026.
For self-hosted deployments, administrators must manually install the patch if automatic updates are not enabled. Systems running older versions must first upgrade to a supported release before applying the fix. In particular, PRA self-hosted customers can resolve the flaw by upgrading to version 25.1.1 or later.
Hacktron AI team reported that roughly 11,000 BeyondTrust Remote Support instances are exposed online across cloud and on-prem environments. Around 8,500 of these are on-prem systems and could remain vulnerable if not patched. The affected deployments are mainly used by large organizations, including enterprises in healthcare, financial services, government, and hospitality sectors.
“At this time, we are withholding technical details to allow affected parties sufficient time to apply patches. We strongly recommend addressing this vulnerability promptly, as exploitation is straightforward.” wrote Hacktron.
