A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support and Privileged Remote Access. Improper validation of authentication data may allow a network-positioned attacker to bypass access controls and gain unauthorized access to the appliance, including accounts with elevated privileges. Exploitation requires a specific authentication configuration to be enabled
Monitor this advisory for an available fix and review any installs of the affected package.
Local check
hol-guard supply-chain scanCritical Pre-Authentication Vulnerability in BeyondTrust Remote Support and Privileged Remote Access affects BeyondTrust/Privileged Remote Access (generic), BeyondTrust/Remote Support (generic). Severity is critical. A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support and Privileged Remote Access. Improper validation of authentication data may allow a network-positioned attacker to bypass access controls and gain unauthorized access to the appliance, including accounts with elevated privileges. Exploitation requires a specific authentication configuration to be enabled
AI coding agents often install or upgrade packages automatically in generic. A critical vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| BeyondTrust/Privileged Remote Accessgeneric |
A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support and Privileged Remote Access. Improper validation of authentication data may allow a network-positioned attacker to bypass access controls and gain unauthorized access to the appliance, including accounts with elevated privileges. Exploitation requires a specific authentication configuration to be enabled
Monitor this advisory for an available fix and review any installs of the affected package.
Local check
hol-guard supply-chain scanCritical Pre-Authentication Vulnerability in BeyondTrust Remote Support and Privileged Remote Access affects BeyondTrust/Privileged Remote Access (generic), BeyondTrust/Remote Support (generic). Severity is critical. A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support and Privileged Remote Access. Improper validation of authentication data may allow a network-positioned attacker to bypass access controls and gain unauthorized access to the appliance, including accounts with elevated privileges. Exploitation requires a specific authentication configuration to be enabled
AI coding agents often install or upgrade packages automatically in generic. A critical vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| BeyondTrust/Privileged Remote Accessgeneric |
| 0 |
| Not reported |
| BeyondTrust/Remote Supportgeneric | 0 | Not reported |
|---|
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| 0 |
| Not reported |
| BeyondTrust/Remote Supportgeneric | 0 | Not reported |
|---|
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard