CVE-2026-40141: BeyondTrust Privileged Remote Access

Critical severity, CVSS 9.9. EPSS: 0.5% chance of exploitation in the next 30 days.

A high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote Access related to the processing of certain input parameters. Insufficient validation of user-supplied input may allow an authenticated attacker with limited privileges to access unintended resources or data beyond their authorization scope. Exploitation is restricted to accounts with specific permissions.

Affected products

  • BeyondTrust Privileged Remote Access: before 25.3.3 (fixed in 25.3.3)
  • BeyondTrust Remote Support: before 25.3.3 (fixed in 25.3.3)

Published 2026-07-06. Last modified 2026-07-07.