/Vulnerability Library

BeyondTrust Remote Support - Unauthenticated WebSocket RCE

CVE-2026-1731
Verified

Description

BeyondTrust Remote Support is vulnerable to unauthenticated remote code execution via the WebSocket endpoint /nw. An attacker can extract the company identifier from the /get_mech_list endpoint and use it to connect to the WebSocket service, then inject OS commands through the binary WebSocket payload that are executed on the server.

Severity

Critical

Exploit Probability

91%

Affected Product

remote_support

Published Date

February 10, 2026

Template Author

attackerkb, hacktron, pdteam

CVE-2026-1731.yaml
9.5Severity

CVSS Metrics

CVE ID:
cve-2026-1731
CWE ID:
cwe-78

References

https://attackerkb.com/topics/jNMBccstay/cve-2026-1731/rapid7-analysishttps://www.hacktron.ai/blog/cve-2026-1731-beyondtrust-remote-support-rcehttps://www.beyondtrust.com/trust-center/security-advisories/bt26-02

Remediation Steps

Apply the latest security patches provided by BeyondTrust for Remote Support and Privileged Remote Access products.