What is CVE-2026-1731?
BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted requests, an unauthenticated remote attacker may be able to execute operating system commands in the context of the site user.
Timeline
- 2026-02-06Published to the U.S. National Vulnerability Database (NVD)
- 2026-02-13Added to the CISA Known Exploited Vulnerabilities (KEV) catalog
- 2026-02-16CISA federal remediation deadline (BOD 22-01)
- 2026-04-22First covered in a defend.network daily briefing
- 2026-06-17NVD record last updated
CISA Known Exploited Vulnerability
BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Vulnerability
Affected product
BeyondTrust Remote Support (RS) And Privileged Remote Access (PRA)
NVD also lists CPE entries for: Beyondtrust Privileged Remote Access, Beyondtrust Remote Support
References
Referenced in our briefings & reports
Browse all tracked CVEs in the defend.network CVE database →
🤖 This CVE page is generated by defend.network from NVD, CISA KEV, EPSS, and our verified daily briefings. Severity and exploitation data come from official sources; always verify remediation steps against the official vendor advisory before acting in production.