SEC Consult Vulnerability Lab Security Advisory < 20260924-0 >
=======================================================================
title: Multiple Vulnerabilities
product: Paessler PRTG Network Monitor
vulnerable version: <26.2.120.1449
fixed version: 26.2.120.1449
CVE number: CVE-2026-4637, CVE-2026-4638
impact: high
homepage:https://www.paessler.com/prtg/prtg-network-monitor
found: 2026-01-29
by: J. Kruchem (Office Vienna)
S. Michlits (Office Vienna)
SEC Consult Vulnerability Lab
An integrated part of SEC Consult, an Atos business
Europe | Asia
https://www.sec-consult.com
=======================================================================
Vendor description:
-------------------
"We provide industry-leading monitoring solutions for businesses of all
sizes, from SMBs to large enterprises. In collaboration with trusted
partners, we address the challenges of ever-evolving infrastructures,
ensuring that businesses can operate without disruption.
Source:https://www.paessler.com/company/about-us
Business recommendation:
------------------------
The vendor provides a patch which should be installed immediately.
SEC Consult highly recommends to perform a thorough security review of the product
conducted by security professionals to identify and resolve potential further
security issues.
Vulnerability overview/description:
-----------------------------------
1) Cross Site Scripting (CVE-2026-4637)
PRTG Security Monitoring reflects the path when trying to acccess a URL which
does not exist. For example, the following URL leads to a 403 forbidden path
error message:
https://<$IP>/not_existing/welcome.htm
```
HTTP/1.1 403 Forbidden Path: /not_existing/
[Error 403: Forbidden Path: /not_existing/]
```
The extension ".htm" is required at the end of the URL. HTML code is not
sanitized in the URL and will be reflected. Unauthorized attackers can
execute arbitrary JavaScript code in the victim's browser in the context
of the attacked PRTG installation.
2) Plaintext Storage of Password (CVE-2026-4638)
A PRTG user can select pre-defined scripts when creating an EXE/Script sensor.
One pre-defined VBScript takes two integers as arguments and returns their
product (e.g. arg1=7 arg2=7, result=49). cscript.exe generally returns
an error if calculating strings. The error contains the string itself.
A documented variable %windowspassword holds the configured domain user
password which can be used as argument for the VBScript and thus gets
reflected as error when trying to run the script.
The PRTG user must not be a read-only user and sensor creation needs to be
allowed (default).
Proof of concept:
-----------------
1) Cross Site Scripting (CVE-2026-4637)
The following URL can be used as a proof of concept reflecting back the
victim's session cookie:
https://<$IP>/<script>alert(document.cookie)</script>/welcome.htm
Since the HttpOnly flag is not set, the cookie will be reflected if a
victim has a session and opens the URL.
```
HTTP/1.1 403 Forbidden Path: /<script>alert(document.cookie)</script>/
[Error 403: Forbidden Path: /<script>alert(document.cookie)</script>/]
```
2) Plaintext Storage of Password (CVE-2026-4638)
The following steps can be performed to reflect the configured domain user
password:
- Create a new sensor EXE/Script
- Select 'Demo VBScript - Multiplies two integers(2 parameters).vbs'
- Use parameter value: '%windowspassword %windowspassword'
- Save
- Click on the refresh symbol to execute the script
- The cscript error in the red paragraph shows the plaintext password
Output:
```
Response not well-formed: "(C:\Program Files (x86)\PRTG Network Monitor\
custom sensors\EXE\Demo VBScript - Multiplies two integers(2 parameters).vbs(6, 1)
Microsoft VBScript runtime error: Type mismatch: '[string: "asdfQWER1234!"]' )"
(code: PE132)
```
Vulnerable / tested versions:
-----------------------------
The following version has been tested which was the latest version available
at the time of the test:
* 25.4.114.1032+
According to the vendor, versions before 26.2.120.1449 are affected.
Vendor contact timeline:
------------------------
2026-01-29: Contacting vendor throughsecurity () paessler com
2026-01-29: Automatic reply that message was received; no further response.
2026-02-09: Following up again, asking for PGP keys.
2026-02-09: Vendor sends PGP key fingerprint, but public PGP key is missing.
2026-02-10: Vendor sends link to PGP key on their website.
Sending encrypted advisory to vendor.
2026-02-11: Vendor confirms receipt of advisory and starts internal review.
2026-03-05: Asking for a status update.
2026-03-06: Vendor responded with update for coming week.
2026-03-10: Another vendor contact responds to our initial email from 29th
January.
2026-03-11: Clarifying that it is the same report and vendor investigation
is already ongoing.
2026-03-23: Vendor stated that the fix will be released in May 27.
2026-03-23: Reserved CVE numbers and communicated them to the vendor.
2026-05-29: Vendor needs to postpone release to 9th July instead of 18th June.
2026-06-03: Vendor fixes issues in version 26.2.120.1449.
2026-06-08: Confirming new release date.
2026-07-02: Vendor drafts communication for customers for the release on 9th July.
2026-07-15: Vendor provides their own security advisory.
2026-07-21: Informing vendor regarding publication delay on our side.
2026-08-12: We will inform vendor regarding release date.
2026-09-23: Planned release for 24th September.
2026-09-24: Public release of security advisory.
Solution:
---------
The vendor provides a patched version 26.2.120.1449 which can be downloaded
from the following URL:
https://www.paessler.com/de/download/
Vendor security advisory:
https://paessler.freshdesk.com/en/support/solutions/articles/76000088640
Workaround:
-----------
None
Advisory URL:
-------------
https://sec-consult.com/vulnerability-lab/
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
SEC Consult Vulnerability Lab
An integrated part of SEC Consult, an Atos business
Europe | Asia
About SEC Consult Vulnerability Lab
The SEC Consult Vulnerability Lab is an integrated part of SEC Consult, an
Atos business. It ensures the continued knowledge gain of SEC Consult in the
field of network and application security to stay ahead of the attacker. The
SEC Consult Vulnerability Lab supports high-quality penetration testing and
the evaluation of new offensive and defensive technologies for our customers.
Hence our customers obtain the most current information about vulnerabilities
and valid recommendation about the risk profile of new technologies.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Interested to work with the experts of SEC Consult?
Send us your applicationhttps://sec-consult.com/career/
Interested in improving your cyber security with the experts of SEC Consult?
Contact our local officeshttps://sec-consult.com/contact/
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Mail: security-research at sec-consult dot com
Web:https://www.sec-consult.com
Blog:http://blog.sec-consult.com
X:https://x.com/sec_consult
EOF J. Kruchem, S. Michlits / @2026
Attachment:
smime.p7s
Description: S/MIME Cryptographic Signature
_______________________________________________ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: https://seclists.org/fulldisclosure/