---
schema: 1
kind: vulnerability
title: "CVE-2026-40138/-40139/-40140/-40141 — BeyondTrust Remote Support / Privileged Remote Access: critical pre-auth bypass, flagged by NCSC-CH"
headline: "NCSC-CH flags critical pre-auth bypass in BeyondTrust RS/PRA appliances (CVE-2026-40138/-40139)"
summary: >
  BeyondTrust advisory BT26-03, flagged by NCSC-CH on 7 July, discloses four flaws in Remote Support and Privileged Remote Access appliances, including two critical pre-authentication bypasses (CVE-2026-40138/-40139) that yield administrative appliance access. Affected RS/PRA ≤ 25.3.2, fixed in 25.3.3; no confirmed exploitation yet, but the product family has a documented history of exploitation to deploy web shells and backdoors.
discovered_at: "2026-07-08T20:35:00Z"
event_date: 2026-07-07
run_id: 2026-07-08T2009Z-intel
priority: high
immediate_action: null
tags:
  - vulnerabilities
  - auth-bypass
  - pre-auth
  - patch-available
  - identity
regions:
  - global
  - switzerland
sectors:
  - public-sector
  - technology
entities: []
cves:
  - id: CVE-2026-40138
    cvss: "9.2"
    epss: null
    type: auth-bypass
    vector: zero-click
    auth: pre-auth
    status:
      - patch-available
    affected: "RS/PRA ≤ 25.3.2"
    fixed: "25.3.3"
  - id: CVE-2026-40139
    cvss: "9.2"
    epss: null
    type: auth-bypass
    vector: zero-click
    auth: pre-auth
    status:
      - patch-available
    affected: "RS/PRA ≤ 25.3.2"
    fixed: "25.3.3"
  - id: CVE-2026-40140
    cvss: "8.7"
    epss: null
    type: dos
    vector: zero-click
    auth: pre-auth
    status:
      - patch-available
    affected: "RS/PRA ≤ 25.3.2"
    fixed: "25.3.3"
  - id: CVE-2026-40141
    cvss: "8.5"
    epss: null
    type: info-disclosure
    vector: zero-click
    auth: post-auth
    status:
      - patch-available
    affected: "RS/PRA ≤ 25.3.2"
    fixed: "25.3.3"
sources:
  - url: "https://security-hub.ncsc.admin.ch/#/posts/12751"
    publisher: "NCSC Switzerland (GovCERT.ch) — Cyber Security Hub"
    date: "2026-07-07"
    role: primary
  - url: "https://www.bleepingcomputer.com/news/security/beyondtrust-warns-of-critical-flaws-in-remote-access-software/"
    publisher: "BleepingComputer"
    date: "2026-07-07"
    role: corroborating
  - url: "https://thehackernews.com/2026/07/beyondtrust-patches-critical-auth.html"
    publisher: "The Hacker News"
    date: "2026-07-07"
    role: corroborating
closed_sources: []
evidence:
  - quote: "Successful exploitation allows unauthenticated attackers to bypass access controls and gain administrative access."
    publisher: "NCSC Switzerland (GovCERT.ch) — Cyber Security Hub"
  - quote: "Exploitation of the critical authentication bypasses requires specific, non-default authentication configurations, which have not been made public, to be enabled on the target appliance."
    publisher: "NCSC Switzerland (GovCERT.ch) — Cyber Security Hub"
verification: multi-source
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
classification: null
watchlist_hit: false
actions:
  - "Patch BeyondTrust Remote Support / Privileged Remote Access to ≥ 25.3.3 now (self-hosted); cloud instances were fixed 2026-04-21."
  - "Until patched, determine whether the non-default authentication configuration required for CVE-2026-40138/-40139 (likely a SAML/OIDC integration) is enabled and disable it if not operationally required; restrict appliance management-plane access to a trusted admin segment."
migrated_from: null
---

NCSC-CH's Cyber Security Hub (GovCERT.ch, TLP:CLEAR) flagged BeyondTrust's 7 July 2026 advisory BT26-03 covering four vulnerabilities in Remote Support (RS) and Privileged Remote Access (PRA) appliances — the vendor's remote-support/PAM software used by IT service desks including government administrations ([NCSC-CH, 2026-07-07](https://security-hub.ncsc.admin.ch/#/posts/12751)). CVE-2026-40138 and CVE-2026-40139 (both CVSS 4.0 9.2, CRITICAL) sit in the shared authentication subsystem: CVE-2026-40138 stems from improper validation of authentication data and CVE-2026-40139 from improper processing of authentication requests, both letting a network-positioned unauthenticated attacker bypass access controls and obtain administrative access — but only where a specific, non-default authentication configuration (unspecified by the vendor) is enabled. CVE-2026-40140 is an unauthenticated DoS in the network-communication subsystem, and CVE-2026-40141 lets a low-privilege authenticated user reach resources beyond their authorization scope. Affected versions are RS/PRA 25.3.2 and earlier, fixed in 25.3.3; BeyondTrust cloud-hosted customers were already patched on 21 April 2026, so self-hosted customers not on auto-update must apply the April security rollup ([BleepingComputer, 2026-07-07](https://www.bleepingcomputer.com/news/security/beyondtrust-warns-of-critical-flaws-in-remote-access-software/)). Neither BeyondTrust nor NCSC-CH reports confirmed in-the-wild exploitation or a public PoC as of this run. **Defender takeaway:** this is a home-authority advisory on a high-value target class — remote-support/PAM appliances broker privileged sessions into the estate, and BeyondTrust RS/PRA flaws have come under repeated exploitation in the past to deploy web shells and backdoors ([The Hacker News, 2026-07-07](https://thehackernews.com/2026/07/beyondtrust-patches-critical-auth.html)); prioritise patching and, given the pre-auth admin-access impact, audit appliance authentication logs for administrative sessions created without a corresponding interactive login.
