HarborGuard / CVE
Back to search
CRITICALCVE-2026-1731Published Modified CNA BT

CVE-2026-1731: Remote code execution vulnerability in BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)

BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted requests, an unauthenticated remote attacker may be able to execute operating system commands in the context of the site user.

Metrics

CVSS v4.0
9.9
Severity
CRITICAL
Fixed in
Affected Products
1
Affected packages
  • BeyondTrust / Remote Support(RS) & Privileged Remote Access(PRA)
    ≤ RS 25.3.1 · ≤ PRA 24.3.4
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:H/SA:L