CVE-2026-1731 PUBLISHED

Remote code execution vulnerability in BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)

Assigner: BT
Reserved: 31.01.2026 Published: 06.02.2026 Updated: 06.02.2026

BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted requests, an unauthenticated remote attacker may be able to execute operating system commands in the context of the site user.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:H/SA:L
CVSS Score: 9.9

Product Status

Vendor BeyondTrust
Product Remote Support(RS) & Privileged Remote Access(PRA)
Versions Default: unaffected
  • affected from 0 to RS 25.3.1 (incl.)
  • affected from 0 to PRA 24.3.4 (incl.)

References

Problem Types

  • CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CWE

Impacts

  • CAPEC-248 Command Injection