S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Feb 10, 2026

CVE-2026-1731 Scanner

CVE-2026-1731 Scanner - Remote Code Execution (RCE) vulnerability in BeyondTrust Remote Support

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.2k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2026-1731
9.9
CVSScritical
Exploitable remotely over the internet · no authentication required.

BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted requests, an unauthenticated remote attacker may be able to execute operating system commands in the context of the site user.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Remote Support(RS) & Privileged Remote Access(PRA)by BeyondTrust
0
Updated Sep 10, 2026View on NVD →
Detail

BeyondTrust Remote Support is a widely used software solution by organizations to provide secure remote support capabilities. It is designed for secure access to remote systems without compromising data security. Businesses and IT service providers utilize this software to troubleshoot and assist end-users effectively. BeyondTrust Remote Support is essential for maintaining system uptime and offers robust features for system administrators. The software is employed in various sectors, including healthcare, finance, and government, to ensure seamless support services. It also integrates with various authentication protocols to provide secure remote access.

The Remote Code Execution (RCE) vulnerability in BeyondTrust Remote Support represents a significant security risk due to its potential to allow unauthorized command execution on the server. By exploiting the WebSocket endpoint, attackers can execute arbitrary commands without authentication. This vulnerability exists due to improper handling of binary WebSocket payloads, which can be manipulated to inject OS commands. The flaw affects systems where outdated security patches are applied, making them susceptible to remote attacks. Exploiting this vulnerability may lead to compromise of sensitive information and system integrity. Security patches must be applied immediately to mitigate this risk.

Technical details of this vulnerability reveal exploitation via the WebSocket endpoint, specifically the `/nw` endpoint, where an attacker can inject commands. Attackers use the `/get_mech_list` endpoint to extract a company identifier, which is then leveraged in the WebSocket connection. The payload is crafted to execute system commands as part of the binary WebSocket frame. The vulnerability allows commands injection due to insufficient input validation and lack of proper security measures. Critical infrastructure and sensitive data are at risk due to this vulnerability if not properly patched. The flaw requires immediate attention to prevent full system compromise.

Exploiting this vulnerability can lead to severe consequences, including unauthorized access and control over the affected systems. Attackers may steal sensitive data, disrupt operations, and cause financial losses. The vulnerability allows attackers to potentially infiltrate the network further, leading to broader system compromises. Organizations may face reputational damage and legal consequences due to security breaches. It poses a critical threat to the integrity and confidentiality of the data stored within affected systems. Preventive measures and timely patch management are crucial to mitigate these risks and secure organizational assets.

REFERENCES

Solution Advice
  • Apply the latest security patches provided by BeyondTrust for Remote Support and Privileged Remote Access products.
  • Regularly update and maintain all software applications to prevent exploitation of known vulnerabilities.
  • Implement network segmentation to limit access to critical systems and services.
  • Conduct periodic security assessments to identify and mitigate potential vulnerabilities.
  • Enhance input validation and security measures to protect against unauthorized command execution.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.