PT-2026-6803 · Beyondtrust · Beyondtrust Remote Support+1
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
BeyondTrust Remote Support versions prior to 25.3.2
BeyondTrust Privileged Remote Access versions prior to 25.1.1
Description
A pre-authentication operating system command injection flaw exists in BeyondTrust Remote Support and Privileged Remote Access. This issue allows an unauthenticated remote attacker to execute arbitrary operating system commands in the context of the site user by sending specially crafted requests. The flaw is rooted in the
thin-scc-wrapper Bash script, which improperly handles the remoteVersion variable during client-server negotiations via the /nw WebSocket endpoint. Exploitation requires a valid X-Ns-Company HTTP header that matches the target system configuration. Approximately 11,000 instances of these products are exposed to the internet, with about 8,500 being on-premises deployments. This issue has been actively exploited in ransomware campaigns, where attackers have used it to deploy remote monitoring tools like SimpleHelp and utilize PowerShell for Active Directory enumeration.Recommendations
Update BeyondTrust Remote Support to version 25.3.2 or apply the BT26-02-RS patch.
Update BeyondTrust Privileged Remote Access to version 25.1.1 or apply the BT26-02-PRA patch.
As a temporary mitigation, restrict access to the
/nw WebSocket endpoint to minimize the risk of exploitation.Exploit
Fix
RCE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Beyondtrust Remote Support
Privileged Remote Access