CVE-2026-1731: BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2026-02-13. EPSS: 91.7% chance of exploitation in the next 30 days.

BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted requests, an unauthenticated remote attacker may be able to execute operating system commands in the context of the site user.

Affected products

  • BeyondTrust Privileged Remote Access: before 25.1 (fixed in 25.1)
  • BeyondTrust Remote Support: before 25.3.2 (fixed in 25.3.2)

Published 2026-02-06. Last modified 2026-06-17.