BeyondTrust Privileged Remote Access (PRA) versions prior to 25.1 are vulnerable to a local authentication bypass. A local authenticated attacker can view the connection details of a ShellJump session that was initiated with external tools, allowing unauthorized access to connected sessions.
2025-05-05T17:18:46.720
2025-11-03T20:17:05.713
Modified
13061848-ea10-403d-bd75-c83a022c2891
CVSSv3.1: 7.8 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | beyondtrust | privileged_remote_access | < 25.1 | Yes |