BeyondTrust Remote Support - Unauthenticated WebSocket RCE
CVE-2026-1731
Verified
Description
BeyondTrust Remote Support is vulnerable to unauthenticated remote code execution via the WebSocket endpoint /nw. An attacker can extract the company identifier from the /get_mech_list endpoint and use it to connect to the WebSocket service, then inject OS commands through the binary WebSocket payload that are executed on the server.
Severity
Critical
Exploit Probability
91%
Affected Product
remote_support
Published Date
February 10, 2026
Template Author
attackerkb, hacktron, pdteam
CVE-2026-1731.yaml
9.5Severity
CVSS Metrics
CVE ID:
cve-2026-1731
CWE ID:
cwe-78
Remediation Steps
Apply the latest security patches provided by BeyondTrust for Remote Support and Privileged Remote Access products.