BeyondTrust Remote Support is vulnerable to unauthenticated remote code execution via the WebSocket endpoint /nw. An attacker can extract the company identifier from the /get_mech_list endpoint and use it to connect to the WebSocket service, then inject OS commands through the binary WebSocket payload that are executed on the server.
id: CVE-2026-1731
info:
name: BeyondTrust Remote Support - Unauthenticated WebSocket RCE
author
...