OpsBuzz

Alert

BeyondTrust Privileged Remote Access PRA and Remote Support RS OS Command Injection Vulnerability

BeyondTrust Privileged Remote Access PRA and Remote Support RS contain an OS command injection vulnerability that can be exploited by an attacker with exis

Security · HIGH
Source: CISA Known Exploited VulnerabilitiesMay 2, 2026, 4:51 PMSecurityhigh

Full content

BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain an OS command injection vulnerability that can be exploited by an attacker with existing administrative privileges to upload a malicious file. Successful exploitation of this vulnerability can allow a remote attacker to execute underlying operating system commands within the context of the site user.

Vendor: BeyondTrust

Product: Privileged Remote Access (PRA) and Remote Support (RS)

Due date: 2025-02-03

Known ransomware use: Unknown

Why it matters

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Related alerts