CVE-2026-40141
privileged_remote_access: Improper Neutralization of Special Elements in Data Query Logic (CVE-2026-40141)
Beschreibung
Ein schwerwiegender Schwachpunkt besteht in einem Webanwendungskomponente von BeyondTrust Remote Support und Privileged Remote Access im Zusammenhang mit der Verarbeitung bestimmter Eingabeparameter. Eine unzureichende Validierung von benutzereingeführten Daten kann es einem authentifizierten Angreifer mit eingeschränkten Berechtigungen ermöglichen, auf nicht beabsichtigte Ressourcen oder Daten zuzugreifen, die über ihren Autorisierungsbereich hinausgehen. Die Ausnutzung ist auf Konten mit bestimmten Berechtigungen beschränkt.
Metriken
Weakness-Klassen (CWE)
CWE-943Class
Improper Neutralization of Special Elements in Data Query Logic
The product generates a query intended to access or manipulate data in a data store such as a database, but it does not neutralize or incorrectly neutralizes special elements that can modify the intended logic of the query.
cwe.mitre.org →
Re-Analyse & Statuswechsel
Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.
- CVE Modified2026-07-06 19:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-40141","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
- New CVE Received2026-07-06 17:16 UTC· 13061848-ea10-403d-bd75-c83a022c2891
- Affected: Remote Support, Privilege Remote Access
- Description: A high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote Access related to the processing of certain input parameters. Insufficient validation of user-supplied input may allow an authenticated attacker with limited privileges to access unintended resources or data beyond their authorization scope. Exploitation is restricted to accounts with specific permissions.
- CVSS V4.0: AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- CWE: CWE-943
Betroffene Produkte
Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.
beyondtrust
privileged_remote_access25.3.3
beyondtrust
remote_support25.3.3