Status: UPDATED | Advisory ID: CVE-2026-40138
| CVE | CVE-2026-40138 |
| CVSS | CVSS 8.1 (High). |
| Affected products | BeyondTrust remote_support |
| Classified as | CWE-287 (Improper Authentication) |
A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support and Privileged Remote Access. Improper validation of authentication data may allow a network-positioned attacker to bypass access controls and gain unauthorized access to the appliance, including accounts with elevated privileges. Exploitation requires a specific authentication configuration to be enabled
| Source | Reference |
|---|---|
| NVD | https://nvd.nist.gov/vuln/detail/CVE-2026-40138 |
| Vendor advisory | https://www.beyondtrust.com/trust-center/security-advisories/bt26-03 |