CVE-2026-1731 Details
Description
BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted requests, an unauthenticated remote attacker may be able to execute operating system commands in the context of the site user.
A critical pre-authentication remote code execution vulnerability has been identified in BeyondTrust Remote Support (RS) versions through 25.3.1 and in Privileged Remote Access (PRA) versions through 24.3.4. This vulnerability allows an unauthenticated remote attacker to execute operating system commands in the context of the site user by sending specially crafted requests. Successful exploitation requires no authentication or user interaction, potentially leading to system compromise, unauthorized access, data exfiltration, and service disruption.
A patch has been applied to all Remote Support SaaS and Privileged Remote Access SaaS customers as of February 2, 2026. Self-hosted customers of Remote Support and Privileged Remote Access should manually apply the patch if their instance is not subscribed to automatic updates. Customers on Remote Support versions older than 21.3 or on Privileged Remote Access versions older than 22.1 will need to upgrade to a newer version to apply this patch. Self-hosted customers of PRA may also upgrade to version 25.1.1 or a newer version to remediate this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://beyondtrustcorp.service-now.com/csm?id=csm_kb_article&sysparm_article=KB0023293 | BeyondTrust | Permissions Required |
| https://www.beyondtrust.com/trust-center/security-advisories/bt26-02 | BeyondTrust | Vendor Advisory |
| https://github.com/win3zz/CVE-2026-1731 | CISA-ADP | ExploitThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-1731 | CISA-ADP | US Government Resource |
| https://www.greynoise.io/blog/reconnaissance-beyondtrust-rce-cve-2026-1731 | CISA-ADP | Third Party Advisory |
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Vulnerability | Feb 13, 2026 | Feb 16, 2026 | Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | BeyondTrust |
Affected Products
| Product | Versions |
|---|---|
| beyondtrust privileged remote access | < 25.1 |
CPE
Remediation
| |
| beyondtrust remote support | < 25.3.2 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | BeyondTrust |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 17, 2026 | Initial Analysis | [email protected] |
| Feb 14, 2026 | CVE Modified | CISA-ADP |
| Feb 13, 2026 | CVE Modified | CISA-ADP |
| Feb 6, 2026 | New CVE Received | BeyondTrust |