Exclusive Webinar: Beyond the Perimeter – How to See Every Threat in Hybrid Networks

CVE-2026-1731

CVE-2026-1731: Critical Security Flaw Impacting BeyondTrust Remote Support and PRA

CVSS Gauge
CVSS Needle

Summary

CVE-2026-1731 is a critical pre-authentication RCE in BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA). It allows attackers to run system commands without authentication, risking full compromise. It affects RS 25.3.1 and earlier and PRA 24.3.4 and earlier. Patches are available and should be applied immediately.

Urgent Actions Required

Which Systems Are Vulnerable to CVE-2026-1731?

Technical Overview

How Does the CVE-2026-1731 Exploit Work?

The attack typically follows these steps:

CVE-2026-1731

What Causes CVE-2026-1731?

Vulnerability Root Cause:

This vulnerability is caused by improper handling of system commands in BeyondTrust products. Classified as OS command injection (CWE-78), it allows attackers to send crafted requests that execute system commands without authentication, potentially compromising the affected system.

How Can You Mitigate CVE-2026-1731?

If immediate patching is delayed or not possible:

  • Limit access to management interfaces using firewall rules or IP allowlists.
  • Remove internet access to exposed instances until updates are applied.
  • Review logs for unusual activity or unauthorized access.

Which Assets and Systems Are at Risk?

Will Patching CVE-2026-1731 Cause Downtime?

Patch application impact: Low. Apply vendor patches or upgrade to fixed versions. SaaS instances were already patched; self-hosted systems require manual updates.

Mitigation (if immediate patching is not possible): Restrict management access with firewall rules or IP allowlists and remove internet exposure until patched.

How Can You Detect CVE-2026-1731 Exploitation?

Exploitation Signatures:

Unusual activity targeting BeyondTrust Remote Support or Privileged Remote Access systems may indicate exploitation attempts.

Indicators of Compromise (IOCs/IOAs):

Behavioral Indicators:

Alerting Strategy:

Remediation & Response

Related Readings

One Platform for All Adversaries

See Fidelis in action. Learn how our fast and scalable platforms provide full visibility, deep insights, and rapid response to help security teams across the World protect, detect, respond, and neutralize advanced cyber adversaries.