
[CIVN-2026-0375] Multiple Vulnerabilities in BeyondTrust
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple Vulnerabilities in BeyondTrust
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: CRITICAL
Software Affected
BeyondTrust Remote Support versions RS 25.3.2 or lower
BeyondTrust Privileged Remote Access versions PRA 25.3.2 or lower
Overview
Multiple vulnerabilities have been reported in BeyondTrust Remote Support (RS) and Privilege Remote Access (PRA), which could allow an attacker to bypass authentication, gain unauthorized access, cause denial-of-service conditions, access unintended resources on the targeted system.
Target Audience:
All end-user organizations and individuals using BeyondTrust.
Risk Assessment:
High risk of denial-of-service, bypass security restrictions, sensitive information disclosure.
Impact Assessment:
Potential for denial-of-service, bypass security restrictions, sensitive information disclosure and/or compromise of system.
Description
BeyondTrust Remote Support (RS) and Privilege Remote Access (PRA) are secure remote access and privileged access management solutions used to provide and manage remote administrative access.
Multiple vulnerabilities have been reported in BeyondTrust due to improper authentication, uncontrolled resource consumption, and improper neutralization of special elements in data query logic. An attacker could exploit these vulnerabilities to bypass authentication, trigger denial-of-service conditions, or access resources beyond their authorization scope on the targeted system.
Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access, access sensitive information, elevate privileges under specific configurations, disrupt service availability, and potentially compromise the targeted system.
Solution
Apply appropriate updates as mentioned by the vendor:
https://www.beyondtrust.com/trust-center/security-advisories/bt26-03
Vendor Information
BeyondTrust
https://www.beyondtrust.com/
References
https://www.beyondtrust.com/trust-center/security-advisories/bt26-03
CVE Name
CVE-2026-40138
CVE-2026-40139
CVE-2026-40140
CVE-2026-40141
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmpiKVEACgkQ3jCgcSdc
ys/9IQ/7BSmheyKdHc9FuXGp+9eS4fEXFX1iKg/jUaTN5Rd4MBuUKzeDoVm9sRpD
qCeFBZw4cm3EKG91oFtZT2jY6plL5ig/QprtFaktcmnfHnZxnGHcOJ93rTrU3JV6
RihlD5aRtBG49b2NtKjPDAJLHeeWCWLEhQHqhZWNnW1ghkTurmMZF2dOwsQLRSVh
yRfmfQZWrcQNlOdGZm3p6+P41neOhQQD7dF8gqrPs+rP46QJaHRY/o0eEt9MYixa
OhwcO4vTMzze63XyAQxMJaweQv00jKq66GcfLClZ5LxvF7XGeZInsBhO8WSmFn8O
WsS2U5r3DXWnzYF/ExbudftzpkhXPGf+1rZzdN3VL9jU11CL6lrvQvnRv8TOsoZ3
by9WU/rYyPIDhil0ltgs+T6P8m+/dLll0pf/GpZoVVE5BNXXGHVrIMiqz/Ro80Rf
8vOLJBSc3axrfQcESHPLu3Lg+NG2BBXn0UGZiTKDRUs1Duu25unmPpoF/Fff3qQM
fr0srrOpbETXqqgHEexMs1EKSNIaI3p4eCiOnVEno5kKqsSxkXJ9bRe6mlXMYzke
oecD1P3fwATA2E7HAIW+Teuh3yDiXKAoV/R+dEcxb5CABhAKFS6HeREBOMFLJE4e
bM5JHNolZMiEQrJpklp+bURuJgrScl/WMJKvhjRMF3WdDbknpLQ=
=r3jf
—–END PGP SIGNATURE—–


