CVE-2026-40140
Analyzed
Analyzed - Analysis Complete
BeyondTrust Remote Support Pre-Authentication DoS Vulnerability
Vulnerability report for CVE-2026-40140, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-07-06
Last updated on: 2026-07-07
Assigner: BeyondTrust
Description
Description
BeyondTrust Remote Support and Privileged Remote Access contain a high-severity pre-authentication vulnerability in the network communication subsystem. Insufficient validation of client-supplied input may allow an unauthenticated remote attacker to trigger a denial-of-service condition affecting appliance availability.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| beyondtrust | privileged_remote_access | to 25.3.3 (exc) |
| beyondtrust | remote_support | to 25.3.3 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-400 | The product does not properly control the allocation and maintenance of a limited resource. |