CVE-2026-40138

Published Jul 6, 2026

Last updated 2 months ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-40138 is a pre-authentication vulnerability found in the authentication subsystem of BeyondTrust Remote Support and Privileged Remote Access products. This flaw, categorized as an improper authentication issue (CWE-287), arises from inadequate validation of authentication data. A network-positioned attacker could exploit this vulnerability to bypass existing access controls and gain unauthorized access to the appliance, potentially with elevated privileges. Successful exploitation is contingent upon a specific authentication configuration being enabled within the affected systems.

Description
A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support and Privileged Remote Access. Improper validation of authentication data may allow a network-positioned attacker to bypass access controls and gain unauthorized access to the appliance, including accounts with elevated privileges. Exploitation requires a specific authentication configuration to be enabled
Source
13061848-ea10-403d-bd75-c83a022c2891
NVD status
Analyzed
Products
privileged_remote_access, remote_support

Risk scores

CVSS 4.0

Type
Secondary
Base score
9.2
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
CRITICAL

CVSS 3.1

Type
Primary
Base score
8.1
Impact score
5.9
Exploitability score
2.2
Vector string
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

13061848-ea10-403d-bd75-c83a022c2891
CWE-287

Social media

Hype score
Not currently trending
  1. 05:11 UTC: CVE-2026-40138 disclosed. 🚨 CVE-2026-40138: Critical Pre-Authentication Vulnerability in BeyondTrust Remote Support and Privileged Remote Access

    @lyrie_ai

    23 Jul 2026

    45 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  2. BeyondTrust has released security updates for multiple vulnerabilities affecting Remote Support and Privileged Remote Access products. The flaws include CVE-2026-40138, CVE-2026-40139, CVE-2026-40140, and CVE-2026-40141, with severity scores reaching as high as 9.9. Successful

    @CloneSystemsInc

    9 Jul 2026

    48 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  3. #BeyondTrust patches four vulnerabilities in Remote Support and PRA: CVE-2026-40138 and CVE-2026-40139 (CVSS 9.2) enable unauthenticated auth bypass including privileged account access. CVE-2026-40140 enables pre-auth DoS; CVE-2026-40141 authenticated authz bypass. #patchrelease

    @MeridianEU

    9 Jul 2026

    46 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Security Bulletin: Critical BeyondTrust Vulnerabilities (CVE-2026-40138 & CVE-2026-40139) BeyondTrust has released fixes for two critical vulnerabilities affecting Remote Support and Privileged Remote Access. https://t.co/RswNaBGYPA

    @RedLegg

    7 Jul 2026

    60 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 🚨 CVE-2026-40138: Critical Pre-Authentication Vulnerability in BeyondTrust Remote Support and Privileged Remote Access Critical Vulnerability Alert! BeyondTrust is affected by CVE-2026-40138. Full Vulnerability Details & Analysis at DarkEye: 🔗 https://t.co/QmccZJA8PU

    @zoomeye_team

    7 Jul 2026

    3356 Impressions

    8 Retweets

    33 Likes

    4 Bookmarks

    0 Replies

    0 Quotes

  6. BeyondTrust patched a critical pre-authentication vulnerability (CVE-2026-40138, CVE-2026-40139, CVE-2026-40140). Update Remote Support instances now. #BeyondTrust #Vulnerability #CVE202640138 #CyberSecurity #RemoteSupport https://t.co/kB7l7n2xfP

    @Daily_CyberSec

    6 Jul 2026

    627 Impressions

    0 Retweets

    6 Likes

    1 Bookmark

    0 Replies

    0 Quotes

Configurations

References

Sources include official advisories and independent security research.