Vulnerability Intelligence Report
High-Severity Vulnerability In Web Application Component of BeyondTrust Remote Support and Privileged Remote Access
CVE-2026-40141
A high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote Access related to the processing of certain input parameters. Insufficient validation of user-supplied input may allow an authenticated attacker with limited privileges to access unintended resources or data beyond their authorization scope. Exploitation is restricted to accounts with specific permissions.
No Active Exploit Signals
CVSS Base Score
8.5
HIGH
EPSS Probability:0.48%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-943 ↗CWE-943 Improper Neutralization of Special Elements in Data Query Logic
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| BeyondTrust | Remote Support | 0 <= 25.3.2 (affected) |
| BeyondTrust | Privilege Remote Access | 0 <= 25.3.2 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.478%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | BeyondTrust Inc. · Vendor · USA |
| Reserved | 2026-04-09T18:36:13 |
| Published | 2026-07-06T16:13:42 |
| Last Updated | 2026-07-07T14:56:42 |
Community Chatter & Buzz