Answer in brief
CVE-2026-40141 records a Critical severity (CVSS 9.9) vulnerability in High-Severity Vulnerability In Web Application Component of BeyondTrust Remote Support and Privileged Remote Access. The current sources do not mark it as known exploited. The current feed maps BeyondTrust/Privilege Remote Access (generic), BeyondTrust/Remote Support (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 9.9. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps BeyondTrust/Privilege Remote Access (generic), BeyondTrust/Remote Support (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| BeyondTrust/Privilege Remote Accessgeneric | 0 | Not reported |
| BeyondTrust/Remote Supportgeneric | 0 | Not reported |
Published upstream
Jul 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Jul 7, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Jul 6, 2026
A high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote Access related to the processing of certain input parameters. Insufficient validation of user-supplied input may allow an authenticated attacker with limited privileges to access unintended resources or data beyond their authorization scope. Exploitation is restricted to accounts with specific permissions.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-40141 records a Critical severity (CVSS 9.9) vulnerability in High-Severity Vulnerability In Web Application Component of BeyondTrust Remote Support and Privileged Remote Access. The current sources do not mark it as known exploited. The current feed maps BeyondTrust/Privilege Remote Access (generic), BeyondTrust/Remote Support (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 9.9. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps BeyondTrust/Privilege Remote Access (generic), BeyondTrust/Remote Support (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| BeyondTrust/Privilege Remote Accessgeneric | 0 | Not reported |
| BeyondTrust/Remote Supportgeneric | 0 | Not reported |
Published upstream
Jul 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Jul 7, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Jul 6, 2026
A high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote Access related to the processing of certain input parameters. Insufficient validation of user-supplied input may allow an authenticated attacker with limited privileges to access unintended resources or data beyond their authorization scope. Exploitation is restricted to accounts with specific permissions.
Quoted source text, attributed separately from HOL analysis.