Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-40138

CVE-2026-40138: BeyondTrust PRA Auth Bypass Vulnerability

CVE-2026-40138 is a critical authentication bypass flaw in BeyondTrust Privileged Remote Access that allows attackers to gain unauthorized access. This post covers technical details, affected versions, impact, and mitigation.

Published:

CVE-2026-40138 Overview

CVE-2026-40138 is a pre-authentication vulnerability in the authentication subsystem of BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA). Improper validation of authentication data allows a network-positioned attacker to bypass access controls and reach the appliance without valid credentials. Successful exploitation can grant access to accounts with elevated privileges, including administrative roles used to manage remote sessions. Exploitation requires a specific authentication configuration to be enabled on the appliance. The flaw is tracked as an improper authentication weakness [CWE-287] and affects both self-hosted and cloud-managed deployments of the affected products.

Critical Impact

A network-based attacker can bypass authentication on BeyondTrust RS and PRA appliances and gain access to privileged accounts without valid credentials when the vulnerable configuration is enabled.

Affected Products

  • BeyondTrust Privileged Remote Access
  • BeyondTrust Remote Support
  • Deployments with the specific vulnerable authentication configuration enabled

Discovery Timeline

Technical Details for CVE-2026-40138

Vulnerability Analysis

The vulnerability resides in the authentication subsystem of BeyondTrust RS and PRA. The subsystem fails to properly validate authentication data submitted by a remote client. An attacker who can reach the appliance over the network can submit crafted authentication material that the subsystem accepts as valid. This bypass grants unauthorized access to the appliance, including accounts with elevated privileges.

BeyondTrust RS and PRA appliances broker privileged remote sessions to internal systems. Access to a privileged account on the appliance can therefore expose downstream infrastructure, session recordings, credential vaults, and jump items. The EPSS probability at publication was approximately 0.417%, and no public exploit code is currently known.

Root Cause

The root cause is improper validation of authentication data in a specific authentication configuration path. When that configuration is enabled, the subsystem trusts attacker-controlled input during the identity verification step instead of enforcing full cryptographic or credential-based verification. The result is an authentication bypass classified under [CWE-287] (Improper Authentication).

Attack Vector

The attack requires network access to the appliance's authentication endpoint. No prior credentials and no user interaction are required. Exploitation is gated by a specific authentication configuration being enabled on the target, which raises attack complexity but does not require local access. Refer to BeyondTrust Security Advisory BT26-03 for the exact configuration conditions and technical details. No verified proof-of-concept code is available at this time.

Detection Methods for CVE-2026-40138

Indicators of Compromise

  • Successful authentication events on RS or PRA appliances from unexpected source IP addresses, particularly for administrative or privileged accounts.
  • Session establishment or configuration changes on the appliance that are not preceded by a matching credential validation event in logs.
  • New or modified jump items, users, or group policies created outside of change windows.
  • Anomalous API calls to the authentication endpoint with malformed or unusual payloads.

Detection Strategies

  • Review appliance authentication logs for successful logins that lack expected multi-factor or identity provider correlation events.
  • Correlate BeyondTrust audit logs with network flow data to identify authentication attempts originating from untrusted network segments.
  • Alert on privilege elevation, administrator creation, or role changes on RS and PRA appliances.
  • Baseline normal administrative access patterns and flag deviations in source IP, geolocation, or time of day.

Monitoring Recommendations

  • Forward BeyondTrust appliance logs to a centralized SIEM or data lake for retention and correlation.
  • Monitor for outbound connections from the appliance to internal targets that were not initiated by a legitimate support session.
  • Enable and monitor session recording integrity checks to detect tampering following a suspected compromise.
  • Track configuration state of the vulnerable authentication option and alert on unauthorized changes.

How to Mitigate CVE-2026-40138

Immediate Actions Required

  • Apply the fixed versions listed in BeyondTrust Security Advisory BT26-03 to all RS and PRA appliances.
  • Identify appliances with the vulnerable authentication configuration enabled and prioritize them for patching.
  • Rotate credentials, API keys, and session tokens for privileged accounts on any appliance that could not be patched immediately.
  • Review recent authentication and administrative activity for signs of unauthorized access.

Patch Information

BeyondTrust has published fixes in advisory BT26-03. Cloud-hosted RS and PRA instances are updated by the vendor. Self-hosted appliance operators must apply the vendor-supplied update package to each appliance. Consult BeyondTrust Security Advisory BT26-03 for the exact fixed build numbers and upgrade procedure.

Workarounds

  • Disable the specific authentication configuration identified by BeyondTrust as required for exploitation until patches are applied.
  • Restrict network reachability of the appliance's administrative and authentication interfaces to trusted management networks only.
  • Enforce multi-factor authentication and integration with a hardened identity provider for all administrative accounts.
  • Place the appliance behind a reverse proxy or web application firewall that can rate-limit and inspect authentication traffic.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.