Back to overview

CVE-2026-1731

CRITICAL KEV CISA Exploitation: ACTIVE Ransomware noto
9.9
CVSS 4.0
Description
BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted requests, an unauthenticated remote attacker may be able to execute operating system commands in the context of the site user.

Metadata

CVE ID
CVE-2026-1731
State
PUBLISHED
Assigner
BT
Reserved
2026-01-31 23:54 UTC
Published
2026-02-06 21:49 UTC
Last updated
2026-02-26 15:04 UTC
Primary CWE
CWE-78
CWE-78 Improper Neutralization of Special Elements used in a…
Vendor / Product
BeyondTrust / Remote Support(RS) & Privileged Remote Access(PRA)
Sources
cve.org  ·  NVD

Severity & Metrics

9.9 CRITICAL CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:H/SA:L
SSVC — CISA Coordinator
Exploitation
ACTIVE
Automatable
yes
Tech. Impact
total
CISA Known Exploited Vulnerability
Vulnerability name
BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Vulnerability
Vendor
BeyondTrust
Product
Remote Support (RS) and Privileged Remote Access (PRA)
Added to KEV
2026-02-13
Due date
2026-02-16
Ransomware
Known use
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA description
BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)contain an OS command injection vulnerability. Successful exploitation could allow an unauthenticated remote attacker to execute operating system commands in the context of the site user. Successful exploitation requires no authentication or user interaction and may lead to system compromise, including unauthorized access, data exfiltration, and service disruption.
Affected products (1)
VendorProductPlatformVersions
BeyondTrust Remote Support(RS) & Privileged Remote Access(PRA) 0 ≤ RS 25.3.1, 0 ≤ PRA 24.3.4
Weakness (CWE)
CWESourceDescription
CWE-78 cna CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.9 CRITICAL 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:H/SA:L
Back to overview