CVE-2026-40141: exploitation status and patch state
CVE-2026-40141
A high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote Access related to the processing of certain input parameters. Insufficient validation of user-supplied input may allow an authenticated attacker with limited privileges to access unintended resources or data beyond their authorization scope. Exploitation is restricted to accounts with specific permissions.
Is CVE-2026-40141 exploited?
Not in the CISA KEV catalog.
Public exploit code: none found in monitored sources.