Known vulnerability record
CVE-2026-1731
BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Vulnerability
Summary
BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Vulnerability
BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)contain an OS command injection vulnerability. Successful exploitation could allow an unauthenticated remote attacker to execute operating system commands in the context of the site user. Successful exploitation requires no authentication or user interaction and may lead to system compromise, including unauthorized access, data exfiltration, and service disruption.
Signals
Keep the signals separate
CVSS severitycriticalScore 9.9 · source BT
EPSS probability89.4%Probability of exploitation in the next 30 days; not severity
CISA KEVKnown exploitedAdded 2026-02-13
Ransomware useknownPreserved as known / unknown, not a truthy default
Timeline
Dates and provenance
- CVE published
- 2026-02-06
- CVE modified
- 2026-02-26
- KEV date added
- 2026-02-13
- Dataset fetched
- 2026-08-21T03:54:59.841Z
Sources
Original records
- https://www.cve.org/CVERecord?id=CVE-2026-1731 ↗
- https://nvd.nist.gov/vuln/detail/CVE-2026-1731 ↗
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-1731 ↗
Version history: normalized permanent page created 2026-08-20. Machine-enriched fields remain source-attributed.