CVE-2026-1731: BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Vulnerability
BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted requests, an unauthenticated remote attacker may be able to execute operating system commands in the context of the site user.
Other sources
BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)contain an OS command injection vulnerability. Successful exploitation could allow an unauthenticated remote attacker to execute operating system commands in the context of the site user. Successful exploitation requires no authentication or user interaction and may lead to system compromise, including unauthorized access, data exfiltration, and service disruption.
— CISA
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1731?
CVE-2026-1731 has been assigned a critical severity rating due to its potential for remote code execution.
How do I fix CVE-2026-1731?
To fix CVE-2026-1731, update to the latest versions of BeyondTrust Remote Support and Privileged Remote Access as instructed by BeyondTrust.
Which products are affected by CVE-2026-1731?
CVE-2026-1731 affects BeyondTrust Remote Support and certain versions of Privileged Remote Access.
Is CVE-2026-1731 an authenticated vulnerability?
No, CVE-2026-1731 is a pre-authentication remote code execution vulnerability, meaning it can be exploited without user authentication.
What can happen if CVE-2026-1731 is exploited?
Exploitation of CVE-2026-1731 allows attackers to execute arbitrary code on the affected systems, leading to potential full system compromise.