BeyondTrust Patches Critical Access Flaw
CriticalExecutive Summary
BeyondTrust has patched a critical remote code execution (RCE) vulnerability, identified as CVE-2026-1731, in its Remote Support and Privileged Remote Access products.
The flaw allows unauthenticated, remote attackers to execute arbitrary OS commands; patches are now available and should be applied immediately.
Vulnerability Details
- Affected Product: BeyondTrust Remote Support (RS) versions 25.3.1 and prior and Privileged Remote Access (PRA) versions 24.3.4 and prior.
- Identifier: CVE-2026-1731
- CVSS Score: 9.9 (Critical).
- Exploitation Status: No known active exploitation.
Risk & Impact
- Triage: Urgent. This vulnerability allows for full system compromise without authentication or user interaction.
- Attack Vector: An unauthenticated remote attacker can send a specially crafted client request to a vulnerable instance to execute operating system commands.
- Ease of Exploit: Straightforward. Technical details are being withheld to allow time for patching.
Action Plan
- Immediate Action: On-premise customers should upgrade to Remote Support version 25.3.2+ or Privileged Remote Access version 25.1.1+. Note: Instances running versions older than RS 21.3 or PRA 22.1 must perform a major version upgrade before the security patch can be applied.
- Workaround: All SaaS instances were automatically patched by BeyondTrust on February 2, 2026. Self-hosted customers must apply patches manually if automatic updates are disabled.
Relevant professional terms
- Remote Code Execution (RCE)
- A class of software vulnerability that allows a malicious actor to execute arbitrary commands or code on a remote machine over a network.
- Authentication
- The process of verifying the identity of a user, process, or device, often as a prerequisite to allowing access to resources in a system.
Source: SecurityWeek
