[CIVN-2026-0375] Multiple Vulnerabilities in BeyondTrust

By Published On: July 23, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Multiple Vulnerabilities in BeyondTrust


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: CRITICAL


Software Affected


BeyondTrust Remote Support versions RS 25.3.2 or lower

BeyondTrust Privileged Remote Access versions PRA 25.3.2 or lower

Overview


Multiple vulnerabilities have been reported in BeyondTrust Remote Support (RS) and Privilege Remote Access (PRA), which could allow an attacker to bypass authentication, gain unauthorized access, cause denial-of-service conditions, access unintended resources on the targeted system.


Target Audience:

All end-user organizations and individuals using BeyondTrust.


Risk Assessment:

High risk of denial-of-service, bypass security restrictions, sensitive information disclosure.


Impact Assessment:

Potential for denial-of-service, bypass security restrictions, sensitive information disclosure and/or compromise of system.


Description


BeyondTrust Remote Support (RS) and Privilege Remote Access (PRA) are secure remote access and privileged access management solutions used to provide and manage remote administrative access.


Multiple vulnerabilities have been reported in BeyondTrust due to improper authentication, uncontrolled resource consumption, and improper neutralization of special elements in data query logic. An attacker could exploit these vulnerabilities to bypass authentication, trigger denial-of-service conditions, or access resources beyond their authorization scope on the targeted system.


Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access, access sensitive information, elevate privileges under specific configurations, disrupt service availability, and potentially compromise the targeted system.


Solution


Apply appropriate updates as mentioned by the vendor:

https://www.beyondtrust.com/trust-center/security-advisories/bt26-03



Vendor Information


BeyondTrust

https://www.beyondtrust.com/


References


 

https://www.beyondtrust.com/trust-center/security-advisories/bt26-03


CVE Name

CVE-2026-40138

CVE-2026-40139

CVE-2026-40140

CVE-2026-40141




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmpiKVEACgkQ3jCgcSdc

ys/9IQ/7BSmheyKdHc9FuXGp+9eS4fEXFX1iKg/jUaTN5Rd4MBuUKzeDoVm9sRpD

qCeFBZw4cm3EKG91oFtZT2jY6plL5ig/QprtFaktcmnfHnZxnGHcOJ93rTrU3JV6

RihlD5aRtBG49b2NtKjPDAJLHeeWCWLEhQHqhZWNnW1ghkTurmMZF2dOwsQLRSVh

yRfmfQZWrcQNlOdGZm3p6+P41neOhQQD7dF8gqrPs+rP46QJaHRY/o0eEt9MYixa

OhwcO4vTMzze63XyAQxMJaweQv00jKq66GcfLClZ5LxvF7XGeZInsBhO8WSmFn8O

WsS2U5r3DXWnzYF/ExbudftzpkhXPGf+1rZzdN3VL9jU11CL6lrvQvnRv8TOsoZ3

by9WU/rYyPIDhil0ltgs+T6P8m+/dLll0pf/GpZoVVE5BNXXGHVrIMiqz/Ro80Rf

8vOLJBSc3axrfQcESHPLu3Lg+NG2BBXn0UGZiTKDRUs1Duu25unmPpoF/Fff3qQM

fr0srrOpbETXqqgHEexMs1EKSNIaI3p4eCiOnVEno5kKqsSxkXJ9bRe6mlXMYzke

oecD1P3fwATA2E7HAIW+Teuh3yDiXKAoV/R+dEcxb5CABhAKFS6HeREBOMFLJE4e

bM5JHNolZMiEQrJpklp+bURuJgrScl/WMJKvhjRMF3WdDbknpLQ=

=r3jf

—–END PGP SIGNATURE—–

Share this article