BeyondTrust Remote Support & PRA Pre-Authentication Remote Code Execution via OS Command Injection (CVE-2026-1731) — Threadlinqs Intelligence
As of 2026-05-30, BeyondTrust Remote Support & PRA Pre-Authentication Remote Code Execution via OS Command Injection (CVE-2026-1731) is a critical-severity vulnerability threat attributed to a China-nexus actor, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 33 indicators of compromise.
Threat ID: TL-2026-0193 · Severity: CRITICAL · CVSS: 9.8 · Status: PATCHED · Category: VULNERABILITY
Attribution: China · FINANCIAL
Critical pre-authentication remote code execution vulnerability (CVE-2026-1731, CVSS 9.8) in BeyondTrust Remote Support and Privileged Remote Access products via OS command injection in the
A critical pre-authentication remote code execution vulnerability (CVE-2026-1731) exists in BeyondTrust Remote Support (RS) versions 21.3 through 25.3.1 and Privileged Remote Access (PRA) versions 24.3.4 and prior. The flaw resides in the thin-scc-wrapper component, which handles incoming WebSocket connections and is directly exposed to the network. During the WebSocket handshake process, the application processes a client-supplied remoteVersion parameter intended for version compatibility validation. Due to insufficient input sanitization, the parameter value is passed into a Bash arithmetic evaluation context using (( ... )) or let constructs. Bash arithmetic contexts evaluate and execute embedded command substitutions such as $(command) before performing the comparison, enabling an unauthenticated remote attacker to inject and execute arbitrary operating system commands in the context of the site user.
The vulnerability was discovered on January 31, 2026, through AI-enabled variant analysis by researchers at Hacktron AI. CVE-2026-1731 is a variant of CVE-2024-12356, which affected the same thin-scc-wrapper component and was exploited by the Chinese state-sponsored group Silk Typhoon (APT27/Emissary Panda) in the December 2024 breach of the U.S. Department of the Treasury. Both vulnerabilities share the same WebSocket endpoint but exploit different code paths. The attack payload format leverages a[$(cmd)]0 to force arithmetic evaluation and execute arbitrary shell commands. BeyondTrust published security advisory BT26-02 on February 6, 2026, and SaaS customers were auto-patched on February 2, 2026.
A proof-of-concept exploit was published to GitHub on February 10, 2026, and active exploitation was observed within hours. By February 11, GreyNoise sensors detected a surge in reconnaissance scanning for vulnerable instances, with a single IP accounting for 86% of sessions via a commercial VPN service in Frankfurt. Two distinct exploit tools were identified via JA4+ fingerprinting: a lightweight 5-header variant shared among the top scanning IPs and an extended 7-header tool used by single-session scanners. CISA added CVE-2026-1731 to the Known Exploited Vulnerabilities (KEV) catalog on February 13, 2026, with an accelerated federal remediation deadline of February 16. Approximately 16,400 instances were identified as potentially vulnerable by Palo Alto Networks Cortex Xpanse, with approximately 8,500 on-premises instances directly exposed to the internet.
Post-exploitation activity documented by Unit 42 includes deployment of VShell (a stealthy Linux backdoor with fileless memory execution capabilities), SparkRAT (a cross-platform open-source Go RAT), SimpleHelp and AnyDesk remote management tools, Cloudflare Tunnel for tunneling, Nezha monitoring agent, and Metasploit Meterpreter on default port 4444. Attackers deployed multiple web shells including one-line PHP eval shells, China Chopper/AntSword-style shells (aws.php), and a password-protected backdoor (file_save.php) using a config STOMPing technique to inject Apache Location directives, restart the service, then overwrite the configuration with a clean backup to evade forensic analysis.
A sophisticated Python-based account takeover script was observed that backs up the admin password hash (User ID 1), generates a new hash via the check_auth binary, injects it into the database, sleeps 60 seconds for attacker access, restores the original hash, and self-destructs. DNS exfiltration scripts were also deployed, converting hostnames to hexadecimal and transmitting via nslookup to attacker-controlled OAST domains with DNS label chunking to bypass strict resolvers. CISA subsequently updated the KEV entry to flag ransomware-related exploitation activity. Targeted sectors include financial services, legal services, high technology, higher education, wholesale/retail, and healthcare, with confirmed exploitation across the United States, France, Germany, Australia, and Canada.
-
Target sectors: financial-services, legal-services, high-technology, higher-education, wholesale-retail, healthcare, government, defense-contractors
Target regions: North America, Europe, Oceania
Related threats
- BeyondTrust Pre-Auth RCE (CVE-2026-1731) — CVSS 9.9, CISA KEV, WebSocket Command Injection, VShell/SparkRAT, 16K+ Exposed Instances, Multi-Sector Campaign
- CVE-2026-1731 — BeyondTrust Pre-Auth RCE, CVSS 9.8, CISA KEV, Actively Exploited — Unauthenticated OS Command Injection in Remote Support & Privileged Remote Access, SimpleHelp RAT Post-Exploitation, Full Domain Control, Silk Typhoon Predecessor Chain
- Storm-1175 Medusa Ransomware Zero-Day Exploitation Campaign (CVE-2026-23760, CVE-2025-10035)
Detections & IOCs
As of 2026-07-27, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 33 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-1731, T1190, T1059.004, T1059.001, T1059.006, T1505.003, T1136.001, T1136.002, T1078.002, T1070.004, T1036