Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksHelp & FAQAPI
  1. Home/
  2. BeyondTrust/
  3. BeyondTrust Identity Security Risk Assessment

BeyondTrust Identity Security Risk Assessment

AI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Secure coding rating: 0/100How this score is computedA product with no known CVEs starts at a neutral score and climbs the longer it goes without one; a product with known CVEs is penalized by severity instead. This one has 23 known CVEs (vendor-level match — see the CVE list below) and is tracked as ~39 days old in our catalog (a stand-in for real release date, which we don't track). The platform admin controls the formula's weights.

Free identity security risk assessment service analyzing identity attack surfaces

by BeyondTrust · beyondtrust.com · source ↗

Known CVEs (23)About this listSourced from the public NVD database, matched by vendor name. Shown here at the vendor level — we don't track per-product/version data, so a listed CVE may affect a different product from this vendor, not necessarily this one. “New” means published within the last 30 days. “Actively exploited” means CISA's Known Exploited Vulnerabilities (KEV) catalog confirms real-world exploitation, not just a theoretical severity score.

RSS ⇢
  • CVE-2026-40141 ↗CRITICAL 9.92026

    A high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote Access related to the processing of certain input parameters. Insufficient valid…

  • CVE-2026-40140 ↗HIGH 7.52026

    BeyondTrust Remote Support and Privileged Remote Access contain a high-severity pre-authentication vulnerability in the network communication subsystem. Insufficient validation of client-supplied inpu…

  • CVE-2026-40139 ↗CRITICAL 9.82026

    A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. Improper processing of authentication requests may allow an unauthenticated remote att…

  • CVE-2026-40138 ↗HIGH 8.12026

    A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support and Privileged Remote Access. Improper validation of authentication data may allow a ne…

  • CVE-2026-1731 ↗⚠ actively exploitedCRITICAL 9.82026

    BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted req…

  • CVE-2026-1232 ↗2026

    A medium-severity vulnerability has been identified in BeyondTrust Privilege Management for Windows versions <=25.7. Under certain conditions, a local authenticated user with elevated privileges may b…

  • CVE-2025-62159 ↗2025

    External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. A vulnerability was discovered in the BeyondTrust provider implementa…

  • CVE-2025-0217 ↗HIGH 7.82025

    BeyondTrust Privileged Remote Access (PRA) versions prior to 25.1 are vulnerable to a local authentication bypass. A local authenticated attacker can view the connection details of a ShellJump session…

  • CVE-2024-4018 ↗HIGH 8.82024

    Improper Privilege Management vulnerability in BeyondTrust U-Series Appliance on Windows, 64 bit (local appliance api modules) allows Privilege Escalation.This issue affects U-Series Appliance: from 3…

  • CVE-2024-4017 ↗HIGH 8.82024

    Improper Privilege Management vulnerability in BeyondTrust U-Series Appliance on Windows, 64 bit (filesystem modules) allows DLL Side-Loading.This issue affects U-Series Appliance: from 3.4 before 4.0…

  • CVE-2024-25083 ↗MEDIUM 6.32024

    An issue was discovered in BeyondTrust Privilege Management for Windows before 24.1. When an low-privileged user initiates a repair, there is an attack vector through which the user is able to execute…

  • CVE-2023-49944 ↗MEDIUM 6.72023

    The Challenge Response feature of BeyondTrust Privilege Management for Windows (PMfW) before 2023-07-14 allows local administrators to bypass this feature by decrypting the shared key, or by locating …

  • CVE-2020-28369 ↗HIGH 7.82023

    In BeyondTrust Privilege Management for Windows (aka PMfW) through 5.7, a SYSTEM installation causes Cryptbase.dll to be loaded from the user-writable location %WINDIR%\Temp.

  • CVE-2020-12614 ↗HIGH 7.82023

    An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6. If the publisher criteria is selected, it defines the name of a publisher that must be present in the certificate (…

  • CVE-2020-12612 ↗HIGH 7.82023

    An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6. When specifying a program to elevate, it can typically be found within the Program Files (x86) folder and therefore…

  • CVE-2020-12615 ↗HIGH 7.82023

    An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6. When adding the Add Admin token to a process, and specifying that it runs at medium integrity with the user owning …

  • CVE-2021-3187 ↗HIGH 8.82023

    An issue was discovered in BeyondTrust Privilege Management for Mac before 5.7. An authenticated, unprivileged user can elevate privileges by running a malicious script (that executes as root from a t…

  • CVE-2020-12613 ↗HIGH 8.82023

    An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6. An attacker can spawn a process with multiple users as part of the security token (prior to Avecto elevation). When…

  • CVE-2023-23632 ↗HIGH 7.82023

    BeyondTrust Privileged Remote Access (PRA) versions 22.2.x to 22.4.x are vulnerable to a local authentication bypass. Attackers can exploit a flawed secret verification process in the BYOT shell jump …

  • CVE-2023-4310 ↗CRITICAL 9.82023

    BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) versions 23.2.1 and 23.2.2 contain a command injection vulnerability which can be exploited through a malicious HTTP request. Success…

  • …and 3 more

Materials

0

No datasheets, whitepapers, case studies, videos, or demos linked yet.

Other Identity Threat Detection and Response products

see all →
  • 8Layers Cloud Identity Threat Detection · 8Layers
  • Abnormal Core Account Takeover Protection · Abnormal Security
  • Abnormal SaaS Account Takeover Protection · Abnormal Security
  • Active Cypher Cypher Scout · Active Cypher
  • Adaptive Authentication · Verosint
  • Akamai Account Protector · Akamai
  • Anetac Identity Vulnerability Platform · Anetac
  • Attic Bouncer · Attic Security