CVE-2026-1731

BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted requests, an unauthenticated remote attacker may be able to execute operating system commands in the context of the site user.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:beyondtrust:privileged_remote_access:*:*:*:*:*:*:*:*
cpe:2.3:a:beyondtrust:remote_support:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-02-06 22:16

Updated : 2026-02-17 13:40


NVD link : CVE-2026-1731

Mitre link : CVE-2026-1731

CVE.ORG link : CVE-2026-1731


JSON object : View

Products Affected

beyondtrust

  • remote_support
  • privileged_remote_access
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')