Critical Authentication Bypass Vulnerabilities Discovered in BeyondTrust Remote Support and Privileged Remote Access
What Happened — BeyondTrust disclosed four critical flaws (CVE‑2026‑40138, CVE‑2026‑40139, CVE‑2026‑40140, CVE‑2026‑40141) affecting Remote Support (RS) and Privileged Remote Access (PRA) versions ≤ 25.3.2. Two of the flaws enable unauthenticated attackers to bypass authentication and gain privileged access; the other two can cause denial‑of‑service or unauthorized data access.
Why It Matters for Compliance & Audit Readiness
- The vulnerabilities strike at the heart of SOC 2 CC6.1 (Logical Access) – a continuous‑compliance program must prove that authentication controls cannot be bypassed.
- Patch‑management evidence and configuration reviews become essential audit artifacts to demonstrate due diligence under CC6.2 (System Operations).
Who Is Affected – Enterprises that deploy BeyondTrust RS/PRA for remote support, privileged access management, or MSP service delivery across technology, financial services, healthcare, and government sectors.
Recommended Actions –
- Apply the April 2026 security roll‑up (or upgrade to RS 25.3.3 / PRA 25.3.3).
- Verify that the specific authentication configuration flagged by BeyondTrust is disabled.
- Capture patch‑status logs and configuration snapshots as SOC 2 evidence.
- Update access‑control policies to reflect the new hardening requirements and train staff on the revised remote‑access procedures.
Source: BleepingComputer
Technical Notes –
- CVE‑2026‑40138 & CVE‑2026‑40139: Improper authentication handling, enabling unauthenticated remote attackers to bypass access controls.
- CVE‑2026‑40140 & CVE‑2026‑40141: Improper request processing leading to DoS or unauthorized resource access.
- Exploitation requires a specific authentication configuration to be enabled; no public exploits observed yet.
Source: Same as above