CVE-2026-1731
Description
BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted requests, an unauthenticated remote attacker may be able to execute operating system commands in the context of the site user.
Summary dbcve.org
BeyondTrust Remote Support and older Privileged Remote Access contain a critical pre-authentication remote code execution vulnerability that allows unauthenticated remote attackers to execute operating system commands in the context of the site user via specially crafted HTTP requests.
Mitigation
Immediately restrict network access to the BeyondTrust interfaces from untrusted networks, and apply vendor patches or upgrade to latest versions of the affected products.