CVE-2024-12686: BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) OS Command Injection Vulnerability

High severity, CVSS 7.2. Actively exploited: in CISA KEV since 2025-01-13. EPSS: 13.7% chance of exploitation in the next 30 days.

A vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) which can allow an attacker with existing administrative privileges to inject commands and run as a site user.

Affected products

  • BeyondTrust Privileged Remote Access: up to and including 24.3.1
  • BeyondTrust Remote Support: up to and including 24.3.1

Published 2024-12-18. Last modified 2026-06-17.