Security Advisory

CVE-2026-40138

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-06 16:12:42
Last updated 2026-07-07 14:59:19
Assigner BT
CVSS score 9.2
State PUBLISHED

Description

A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support and Privileged Remote Access. Improper validation of authentication data may allow a network-positioned attacker to bypass access controls and gain unauthorized access to the appliance, including accounts with elevated privileges. Exploitation requires a specific authentication configuration to be enabled