CVE-2026-1731 is a critical pre-authentication RCE vulnerability (CVSS 9.9) in BeyondTrust remote support software, affecting the thin-scc-wrapper component via WebSocket connections. The flaw stems from unsanitized bash arithmetic evaluation of the remoteVersion parameter, allowing OS command injection without credentials.
Table of contents
Executive SummaryDetails of CVE-2026-1731Current Scope of Attacks Exploiting CVE-2026-1731Historic ContextInterim GuidanceUnit 42 Managed Threat Hunting QueriesConclusionPalo Alto Networks Product Protections for CVE-2026-1731Indicators of CompromiseSort: