Critical Pre‑Auth Bypass (CVE‑2026‑40138) in BeyondTrust Remote Support & Privileged Remote Access (PRA)
What It Is — BeyondTrust disclosed two critical flaws in its Remote Support (RS) and Privileged Remote Access (PRA) solutions. The primary issue, CVE‑2026‑40138, is a pre‑authentication vulnerability that lets an unauthenticated attacker assume full control of a target device. A second, related flaw (not CVE‑listed in the source) compounds the risk for the same product line.
Exploitability — The vulnerability is rated CVSS 9.2 (Critical). Proof‑of‑concept code has been published, and the flaw can be triggered over the network without any credentials.
Affected Products — BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) versions prior to the July 2026 patches.
Why It Matters for Compliance & Audit Readiness
- SOC 2 Access Control criteria (CC6.1, CC6.2) require that privileged access be tightly managed and that unauthenticated takeover is impossible; this flaw directly violates that expectation.
- Continuous monitoring of privileged‑session logs becomes essential evidence that you can detect and respond to unauthorized control attempts.
- Enterprise buyers now demand proof of remediation and robust access‑control policies as part of SOC 2 attestations; unpatched systems can break that trust chain.
Recommended Actions
- Deploy the July 2026 BeyondTrust patches immediately on all RS/PRA endpoints.
- Review and tighten privileged‑access policies: enforce MFA, least‑privilege, and session‑recording for all remote‑access accounts.
- Update SOC 2 evidence artifacts (configuration baselines, patch‑management logs, privileged‑session audit trails) to reflect remediation.
- Conduct a targeted control‑mapping exercise to confirm that the Access Control criteria are fully satisfied post‑patch.
Source: The Hacker News – BeyondTrust patches critical auth bypass flaws