CRITICAL

CVE-2026-1731

Beyondtrust Privileged Remote Access 2026-02-06 CVSS v3.1
CVSS
9.8
KEV

Description

BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted requests, an unauthenticated remote attacker may be able to execute operating system commands in the context of the site user.

Summary dbcve.org

BeyondTrust Remote Support and older Privileged Remote Access contain a critical pre-authentication remote code execution vulnerability that allows unauthenticated remote attackers to execute operating system commands in the context of the site user via specially crafted HTTP requests.

Mitigation

Immediately restrict network access to the BeyondTrust interfaces from untrusted networks, and apply vendor patches or upgrade to latest versions of the affected products.

Proof of Concept

Weakness (CWE)

CWE-78 OS Command Injection

EPSS Score

89.5%
Probability of exploitation in next 30 days
99.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE