CVE-2026-1731
BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted requests, an unauthenticated remote attacker may be able to execute operating system commands in the context of the site user.
- Affected products
- Beyondtrust Remote Support, Privileged Remote Access
- Beyondtrust Privileged Remote Access
- < 25.1
- Beyondtrust Remote Support
- < 25.3.2
- Fix
- Available
- CVSS 4.0
- 9.9 CRITICAL
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 89.5% (100th percentile)
- Weakness
- CWE-78
- NVD status
- Analyzed
- Published
- 2026-02-06
- Attack patterns
- CAPEC-248
CVE-2026-1731 at NVD
15 known exploits for CVE-2026-1731
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-2026-1731
cve-2026-1731-scanner
CVE-2026-1731
CVE-2026-1731
beyondtrust-rce-scanner
Exploit for OS Command Injection in Beyondtrust Privileged_Remote_Access
Exploit for OS Command Injection in Beyondtrust Privileged_Remote_Access
π BeyondTrust PRA / RS Unauthenticated Remote Code Execution
Exploit for OS Command Injection in Beyondtrust Privileged_Remote_Access
Exploit for OS Command Injection in Beyondtrust Privileged_Remote_Access
Exploit for OS Command Injection in Beyondtrust Privileged_Remote_Access
π BeyondTrust Remote Support / Privileged Remote Access Remote Code Execution
Exploit for CVE-2026-1731
Exploit for CVE-2026-1731
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) unauthenticated Remote Code Execution