Attackers can bypass authentication to gain direct access to BeyondTrust remote support appliances
馃毃 A critical authentication bypass in BeyondTrust Remote Support and Privileged Remote Access allows attackers to jump directly into the appliance. This vulnerability can grant access to accounts with elevated privileges if a specific configuration is active. Patch your appliances immediately to close this gap.
Summary
A critical pre-authentication vulnerability has been identified within the authentication subsystem of Beyond0Trust Remote Support and Privileged Remote Access products. The flaw, tracked as CVE-2026-40138, carries a CVSS score of 9.2. It allows a network-positioned attacker to bypass existing access controls.
Successful exploitation enables unauthorized entry into the appliance, potentially granting control over accounts that hold elevated privileges. This vulnerability exists before any user has authenticated to the system.
Technical details
The vulnerability stems from improper validation of authentication data within the core authentication subsystem. Because the flaw resides in the pre-authentication phase, an attacker does not need valid credentials to attempt an exploit.
An attacker must be positioned on the network to reach the appliance and trigger the bypass. The impact of this vulnerability is highly dependent on the environment; specifically, exploitation requires a certain authentication configuration to be enabled for the bypass to succeed.
If these conditions are met, the attacker can circumvent security checks to gain unauthorized access to the management interface or underlying system functions.
Why this matters for defenders
This flaw targets the very mechanism intended to gatekeep your remote access tools. Because BeyondTrust products often manage highly privileged sessions, a bypass here represents a significant risk to the entire administrative perimeter.
The ability to gain access to accounts with elevated privileges means an attacker could potentially move laterally or take full control of the remote support environment. Defenders should treat this as a high-priority remediation task due to the critical nature of the affected products and the severity of the bypass.
Defender guidance
Verify your current BeyondTrust configuration immediately. The vulnerability's success is tied to specific authentication settings; identifying whether those settings are active in your environment is a priority.
Apply the security updates provided by the vendor to all instances of Remote Support and Privileged Remote Access. Since this is a pre-authentication flaw, network-level mitigations may be difficult if the attacker can reach the appliance directly via the network. Patching remains the primary defense.
