BeyondTrust RCE flaw allows hackers to execute code without logging in


  • BeyondTrust Warns of Critical RCE CVE-2026-1731 Flaw in RS and PRA
  • The vulnerability allows execution of unauthenticated operating system commands, risking compromise and data exfiltration.
  • Patch released February 2, 2026; ~11,000 instances exposed, primarily on-premises deployments

US cybersecurity firm BeyondTrust has warned customers that its Remote Support (RS) product, as well as some older versions of Privileged Remote Access (PRA), are vulnerable to a remote code execution flaw that allows malicious actors to execute operating system commands in the context of the site user.

In a security advisory posted on the company’s page earlier this week, BeyondTrust said the bug, stemming from an operating system command injection weakness, is tracked as CVE-2026-1731 and received a severity score of 9.9/10 (critical).

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top