CVE-2026-40139: Critical Pre-Authentication Vulnerability in BeyondTrust Remote Support and Privileged Remote Access
A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. Improper processing of authentication requests may allow an unauthenticated remote attacker to bypass access controls and gain unauthorized access to the appliance, including accounts with elevated privileges. Exploitation requires a specific authentication configuration to be enabled.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40139?
CVE-2026-40139 has a severity rating of 80, indicating a critical risk level.
How do I fix CVE-2026-40139?
To fix CVE-2026-40139, apply the security patches provided by BeyondTrust for the affected versions of Remote Support.
What impact does CVE-2026-40139 have on my systems?
CVE-2026-40139 may allow unauthenticated remote attackers to bypass access controls and gain unauthorized access to sensitive accounts.
Which versions of BeyondTrust Remote Support are affected by CVE-2026-40139?
CVE-2026-40139 affects specific versions of BeyondTrust Remote Support, so it's important to consult BeyondTrust's advisory for details.
Is CVE-2026-40139 exploited in the wild?
Current indications suggest that CVE-2026-40139 could be subject to exploitation, highlighting the urgency of applying the fix.