CVE-2026-40139 -- CVSS 9.8 Vulnerability Briefing
CVE-2026-40139 | CVSS 9.8 (Critical) | Exploit: No known exploit
What Is It
CVE-2026-40139 is a critical pre-authentication vulnerability in the authentication subsystem of BeyondTrust Remote Support and BeyondTrust Privileged Remote Access, allowing unauthenticated remote attackers to interact with the affected systems without valid credentials.
Technical Detail
The flaw stems from improper processing of authentication requests within the authentication subsystem, meaning the application fails to correctly validate or handle certain inputs before authentication is completed. An unauthenticated remote attacker can send a specially crafted request to trigger this condition without supplying valid credentials. Depending on the specific code path reached, successful exploitation could result in authentication bypass, unauthorized access to privileged remote access sessions, or potentially remote code execution on the underlying host, given the CVSS score of 9.8.
Exploitation Status
No known exploit has been publicly documented or observed as of July 13, 2026. This vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities catalog. No proof-of-concept code has been confirmed in public repositories. The absence of known exploitation does not reduce urgency given the critical severity rating and the high-value nature of the affected products.
Who Is Targeting This
No specific threat actor attribution at this time. Neither confirmed nor reported threat actor associations have been established for this CVE. BeyondTrust products have historically attracted interest from sophisticated actors targeting privileged access infrastructure, but no campaign or actor has been linked to this specific vulnerability.
What To Do
Organizations running BeyondTrust Remote Support or Privileged Remote Access should treat this as a priority patch given the pre-authentication nature of the flaw and the critical CVSS score of 9.8. Apply vendor-supplied patches immediately upon availability and verify patch status across all deployed instances. If patching cannot be completed immediately, restrict network access to the BeyondTrust appliance management interfaces to trusted IP ranges only, and disable external-facing access where operationally feasible. Monitor authentication logs for anomalous or malformed request patterns targeting the authentication subsystem. Review BeyondTrust's official security advisory for specific version guidance and any interim mitigations the vendor has published.