CVE-2026-40141: BeyondTrust Privileged Remote Access
Critical severity, CVSS 9.9. EPSS: 0.5% chance of exploitation in the next 30 days.
A high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote Access related to the processing of certain input parameters. Insufficient validation of user-supplied input may allow an authenticated attacker with limited privileges to access unintended resources or data beyond their authorization scope. Exploitation is restricted to accounts with specific permissions.
Affected products
- BeyondTrust Privileged Remote Access: before 25.3.3 (fixed in 25.3.3)
- BeyondTrust Remote Support: before 25.3.3 (fixed in 25.3.3)
Published 2026-07-06. Last modified 2026-07-07.