CVE-2026-1731 is a critical pre-authentication RCE vulnerability (CVSS 9.9) in BeyondTrust remote support software, affecting the thin-scc-wrapper component via WebSocket connections. The flaw stems from unsanitized bash arithmetic evaluation of the remoteVersion parameter, allowing OS command injection without credentials.

13m read time From unit42.paloaltonetworks.com
Post cover image
Table of contents
Executive SummaryDetails of CVE-2026-1731Current Scope of Attacks Exploiting CVE-2026-1731Historic ContextInterim GuidanceUnit 42 Managed Threat Hunting QueriesConclusionPalo Alto Networks Product Protections for CVE-2026-1731Indicators of Compromise

Sort: