CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

BeyondTrust RS/PRA pre-auth authentication bypass (CVSS4 9.2), NCSC-CH BT26-03

cve · CVE-2026-40139

Coverage
1
first 2026-07-08 → last 2026-07-08
Latest activity
2026-07-08
NCSC-CH flags critical pre-auth bypass in BeyondTrust RS/PRA appliances (CVE-2026-40138/-40139)
Peak priority
high
1 high
Targets
public-sector
sectors: public-sector, technology · regions: switzerland
Sources cited
3
3 hosts

Action items (2)

Do-now tasks recorded on the entries about CVE-2026-40139, newest first. Check the date before acting on an older one.

  • Patch BeyondTrust Remote Support / Privileged Remote Access to ≥ 25.3.3 now (self-hosted); cloud instances were fixed 2026-04-21.
    2026-07-08CVE-2026-40138 +3
  • Until patched, determine whether the non-default authentication configuration required for CVE-2026-40138/-40139 (likely a SAML/OIDC integration) is enabled and disable it if not operationally required; restrict appliance management-plane access to a trusted admin segment.
    2026-07-08CVE-2026-40138 +3

Defender insights

What each entry about CVE-2026-40139 tells a defender to do, newest first.

2026-07-08HIGHNCSC-CH flags critical pre-auth bypass in BeyondTrust RS/PRA appliances (CVE-2026-40138/-40139)

Story timeline

  1. 2026-07-08CVE-2026-40138/-40139/-40140/-40141, BeyondTrust Remote Support / Privileged Remote Access: critical pre-auth bypass, flagged by NCSC-CH
    trending-vulnerabilitiesNCSC-CH flags critical pre-auth bypass in BeyondTrust RS/PRA appliances (CVE-2026-40138/-40139)

Entries about BeyondTrust RS/PRA pre-auth authentication bypass (CVSS4 9.2), NCSC-CH BT26-03 (1)

2026-07-08 · view entry permalink →

CVE-2026-40138/-40139/-40140/-40141, BeyondTrust Remote Support / Privileged Remote Access: critical pre-auth bypass, flagged by NCSC-CH

NCSC-CH's Cyber Security Hub (GovCERT.ch, TLP:CLEAR) flagged BeyondTrust's 7 July 2026 advisory BT26-03 covering four vulnerabilities in Remote Support (RS) and Privileged Remote Access (PRA) appliances, the vendor's remote-support/PAM software used by IT service desks including government administrations (NCSC-CH, 2026-07-07). CVE-2026-40138 and CVE-2026-40139 (both CVSS 4.0 9.2, CRITICAL) sit in the shared authentication subsystem: CVE-2026-40138 stems from improper validation of authentication data and CVE-2026-40139 from improper processing of authentication requests, both letting a network-positioned unauthenticated attacker bypass access controls and obtain administrative access, but only where a specific, non-default authentication configuration (unspecified by the vendor) is enabled. CVE-2026-40140 is an unauthenticated DoS in the network-communication subsystem, and CVE-2026-40141 lets a low-privilege authenticated user reach resources beyond their authorization scope. Affected versions are RS/PRA 25.3.2 and earlier, fixed in 25.3.3; BeyondTrust cloud-hosted customers were already patched on 21 April 2026, so self-hosted customers not on auto-update must apply the April security rollup (BleepingComputer, 2026-07-07). Neither BeyondTrust nor NCSC-CH reports confirmed in-the-wild exploitation or a public PoC as of this run.

Successful exploitation allows unauthenticated attackers to bypass access controls and gain administrative access.

Exploitation of the critical authentication bypasses requires specific, non-default authentication configurations, which have not been made public, to be enabled on the target appliance.

NCSC Switzerland (GovCERT.ch), Cyber Security Hub 2026-07-07
vulnerability08 Jul 20:35Zmulti-sourceOpen finding →

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Vulns1

Source distribution

  • bleepingcomputer.com1 (33%)
  • security-hub.ncsc.admin.ch1 (33%)
  • thehackernews.com1 (33%)