Skip to content
COOEY

FAIL › dossier

BeyondTrust

COMPANY FEDRAMP MARKET

FedRAMP provider · · dossier confidence 20%

BeyondTrust has experienced a series of critical security failures, indicating a need for rigorous security reviews and a commitment to timely patching of vulnerabilities.

PROFILE
CategoryCybersecurityWhat they doBeyondTrust provides privileged access management solutions that allow organizations to secure and manage remote access to systems and applications. Websitehttps://www.beyondtrust.com ↗
SECURITY POSTURE

BeyondTrust has faced multiple critical vulnerabilities that have been exploited by attackers, indicating a potential lack of robust security practices and post-purchase integration.

Notable failures
  • CVE-2026-1731: Critical (RCE) vulnerability in BeyondTrust Remote Support and Privileged Remote Access.
  • CVE-2025-12686: High (RCE) vulnerability in BeyondTrust Privileged Remote Access and Remote Support.
  • CVE-2024-12356: High (RCE) vulnerability in BeyondTrust Privileged Remote Access and Remote Support.
  • CVE-2026-40141: Critical (RCE) vulnerability in a web application component of BeyondTrust Remote Support and Privileged Remote Access.
  • CVE-2026-40139: Critical (pre-authentication RCE) vulnerability in the authentication subsystem of BeyondTrust Remote Support.
Patterns: Repeated unpatched edge-device RCE vulnerabilities.; High-severity vulnerabilities in web application components.; Pre-authentication vulnerabilities in authentication subsystems.
FAILURE HISTORY · 5
DATEEVENTSEVSUMMARY
2026-02-13 CVE-2026-1731 critical BeyondTrust Remote Support and Privileged Remote Access suffered an unpatched OS command injection flaw allowing unauthenticated remote attackers to execute arbitrary system commands.
2024-12-19 CVE-2024-12356 high BeyondTrust PRA/RS allows unauthenticated attackers to execute commands as site users via command injection.
2025-01-13 CVE-2024-12686 high BeyondTrust PRA/RS allows attackers with admin access to upload malware and execute OS commands via command injection.
2026-07-06 CVE-2026-40141 critical A high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote Access related to the processing of certain input parameters. Insufficient validation of user-supplied input may allow an authenticated attacker with limited pr
2026-07-06 CVE-2026-40139 critical A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. Improper processing of authentication requests may allow an unauthenticated remote attacker to bypass access controls and gain unauthorized access to the appliance, i
FEDRAMP CATALOG PRODUCTS · 1
PRODUCTSTATUSIMPACT
Secure Remote AccessIn ProcessModerate
Open questions: How has BeyondTrust addressed these vulnerabilities? · What improvements has the company made to its security posture?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-24 03:46:12.061642+00:00