Independent perspective. Actionable security.Know what matters · Reduce exposure

Vulnerability Assurance / Intelligence

BeyondTrust RS and PRA OS Command Injection (CVE-2026-1731)

Historical catalog analysis: CISA added this entry on February 13, 2026. The entry reflects catalog information retrieved on August 31, 2026, not a snapshot archived on the inclusion date. Check current vendor guidance before acting.

What the vulnerability is

CVE-2026-1731 is an OS command injection vulnerability (CWE-78) affecting BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA). The flaw allows an unauthenticated remote attacker to execute operating system commands with the privileges of the site user. This execution requires no user interaction and no prior authentication, creating a path for full system compromise, data exfiltration, or service disruption.

Exposure and applicability

This vulnerability applies to organizations deploying BeyondTrust RS or PRA. Because the exploit is unauthenticated and requires no interaction, any instance of these products exposed to the internet is at high risk. The source indicates that this vulnerability is known to be used in ransomware campaigns, significantly increasing the urgency for infrastructure owners to identify affected assets.

Remediation priorities

Based on the reported exploitation by ransomware actors, we analyze the following priority actions:

  1. Immediate Mitigation Application: Prioritize applying vendor-supplied mitigations as detailed in the BeyondTrust security advisory. For cloud-based deployments, follow applicable BOD 22-01 guidance.
  2. Compromise Assessment: Because this vulnerability is actively exploited, organizations should inspect all internet-accessible instances for signs of prior compromise. Applying a fix to an already compromised system does not remove the attacker.
  3. Product Decommissioning: In scenarios where vendor mitigations are unavailable or cannot be applied, the product should be discontinued to eliminate the exposure path.

How to validate remediation

Verification must move beyond simple version checks. To assure that exposure has been reduced, defenders should:
* Verify Mitigation State: Confirm through configuration audits or vendor-provided tools that the specific mitigation is active and functioning as intended.
* Evidence of Non-Exploitability: Use authorized security testing to confirm that unauthenticated OS command injection attempts are blocked by the applied fix.
* Post-Remediation Audit: Review system logs for unauthorized site user activity occurring immediately prior to and after the remediation window to ensure no persistence was established.

Limits and open questions

Applying a patch or mitigation reduces the likelihood of future exploitation but does not guarantee that a system is clean if it was previously exposed. There remains residual risk if attackers established persistence before the fix was applied. The source does not provide specific version numbers; defenders must refer to the vendor’s trust center to determine exactly which builds are affected.

Source and editorial note

CVE-2026-1731: BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Vulnerability · Source date: February 13, 2026 · Retrieved August 31, 2026.

Material facts are tied to the cited primary source. Recommendations are independent defensive analysis unless attributed to the source. Confirm consequential decisions against current authoritative guidance.

Archive date: February 16, 2026. The displayed post date is assigned three days after the source date to organize this retrospective archive; it does not mean this site published the analysis then. First published by this site: September 20, 2026 at 00:54 UTC.

Request a Vulnerability Assessment

Turn security intelligence into action.

Discuss your exposure, priorities, and the evidence needed to validate the outcome.

Request a security assessment ↗

Turn security intelligence into action.

Understand exposure, prioritize the response, and define evidence for the outcome.

Request a Security Assessment