← Back to browse · API

CVE-2026-1731

Severity
CRITICAL
CVSS
9.9
EPSS
0.88115
Risk score
95.44
CISA KEV
Yes
PoC
Yes
Published
2026-02-13
Modified
2026-02-13
First seen
2026-08-07
Aliases
EUVD-2026-5559, GHSA-P5WR-5P37-2WM6
Products
BeyondTrust:Remote Support (RS) and Privileged Remote Access (PRA), BeyondTrust:Remote Support(RS) & Privileged Remote Access(PRA) 0 ≤PRA 24.3.4, BeyondTrust:Remote Support(RS) & Privileged Remote Access(PRA) 0 ≤RS 25.3.1
Sources
euvd EUVD-2026-5559
cisa.gov CVE-2026-1731
packetstorm e1b15243aca2ad53b47ce4cf|CVE-2026-1731

Description

BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)contain an OS command injection vulnerability. Successful exploitation could allow an unauthenticated remote attacker to execute operating system commands in the context of the site user. Successful exploitation requires no authentication or user interaction and may lead to system compromise, including unauthorized access, data exfiltration, and service disruption.

References