VendorsBeyondTrustprivileged_remote_accessall versions
Vulnerabilities

BeyondTrust Privileged Remote Access

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

11CVEs
CVE-2026-1731
Remote code execution vulnerability in BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)
Published 2026-02-06 · Analyzed
9.9KEVEPSS 0.907
CVE-2026-40141
High-Severity Vulnerability In Web Application Component of BeyondTrust Remote Support and Privileged Remote Access
Published 2026-07-06 · Analyzed
9.9EPSS 0.005
CVE-2024-12356
Command Injection Vulnerability in Remote Support(RS) & Privileged Remote Access (PRA)
Published 2024-12-17 · Analyzed
9.8KEVEPSS 0.873
CVE-2023-4310
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) versions 23.2.1 and 23.2.2 contain a command injection vulnerability which can be exploited through a malicious HTTP request. Successful exploitation of this vulnerability can allow an unauthenticated remote attacker to execute underlying operating system commands within the context of the site user. This issue is fixed in version 23.2.3.
Published 2023-09-05 · Modified
9.8EPSS 0.019
CVE-2025-5309
Remote Support & Privileged Remote Access server side template injection
Published 2025-06-16 · Analyzed
9.8EPSS 0.009
CVE-2026-40139
Critical Pre-Authentication Vulnerability in BeyondTrust Remote Support and Privileged Remote Access
Published 2026-07-06 · Analyzed
9.8EPSS 0.008
CVE-2026-40138
Critical Pre-Authentication Vulnerability in BeyondTrust Remote Support and Privileged Remote Access
Published 2026-07-06 · Analyzed
9.2EPSS 0.005
CVE-2026-40140
High-Severity Pre-Authentication Vulnerability in BeyondTrust Remote Support and Privileged Remote Access
Published 2026-07-06 · Analyzed
8.7EPSS 0.006
CVE-2023-23632
BeyondTrust Privileged Remote Access (PRA) versions 22.2.x to 22.4.x are vulnerable to a local authentication bypass. Attackers can exploit a flawed secret verification process in the BYOT shell jump sessions, allowing unauthorized access to jump items by guessing only the first character of the secret.
Published 2023-10-12 · Modified
7.8EPSS 0.002
CVE-2025-0217
Privileged Remote Access Authentication Bypass
Published 2025-05-05 · Modified
7.8EPSS 0.002
CVE-2024-12686
Command Injection vulnerability in Remote Support(RS) & Privilege Remote Access (PRA)
Published 2024-12-18 · Analyzed
7.2KEVEPSS 0.137