AUGUST 25, 2026
Live Feed
Back to database
Case File

CVE-2026-40141

CRITICAL · CVSS 9.9 EPSS 0.49% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-06 · Last synced 2026-08-05

CyberRota Analysis

AI-Generated

A critical vulnerability in the web application component of BeyondTrust Remote Support and Privileged Remote Access allows authenticated attackers with limited privileges to exploit insufficient validation of user-supplied input, potentially accessing unauthorized resources or data. Organizations using these products should prioritize remediation efforts, especially those with users holding specific permissions that could be leveraged for exploitation. Immediate action is necessary to mitigate the risk of unauthorized data exposure or resource access.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-40141
Severity
CRITICAL
CVSS
9.9
EPSS
0.49%

Original NVD Description

A high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote Access related to the processing of certain input parameters. Insufficient validation of user-supplied input may allow an authenticated attacker with limited privileges to access unintended resources or data beyond their authorization scope. Exploitation is restricted to accounts with specific permissions.

Related CVEs

Other vulnerabilities affecting the same vendor(s)