SEC Consult SA-20260924-0 :: Multiple Vulnerabilities in Paessler PRTG Network Monitor #CVE-2026-4637 #CVE-2026-4638
Full Disclosuremailing list archivesFrom: SEC Consult Vulnerability Lab via Full 2026-10-6 17:44:41 Author: seclists.org(查看原文) 阅读量:0 收藏

fulldisclosure logo

Full Disclosure mailing list archives


From: SEC Consult Vulnerability Lab via Fulldisclosure <fulldisclosure () seclists org>
Date: Thu, 1 Oct 2026 10:57:56 +0000

SEC Consult Vulnerability Lab Security Advisory < 20260924-0 >
=======================================================================
              title: Multiple Vulnerabilities
            product: Paessler PRTG Network Monitor
 vulnerable version: <26.2.120.1449
      fixed version: 26.2.120.1449
         CVE number: CVE-2026-4637, CVE-2026-4638
             impact: high
           homepage:https://www.paessler.com/prtg/prtg-network-monitor
              found: 2026-01-29
                 by: J. Kruchem (Office Vienna)
                     S. Michlits (Office Vienna)
                     SEC Consult Vulnerability Lab

                     An integrated part of SEC Consult, an Atos business
                     Europe | Asia

                     https://www.sec-consult.com

=======================================================================

Vendor description:
-------------------
"We provide industry-leading monitoring solutions for businesses of all
sizes, from SMBs to large enterprises. In collaboration with trusted
partners, we address the challenges of ever-evolving infrastructures,
ensuring that businesses can operate without disruption.

Source:https://www.paessler.com/company/about-us


Business recommendation:
------------------------
The vendor provides a patch which should be installed immediately.

SEC Consult highly recommends to perform a thorough security review of the product
conducted by security professionals to identify and resolve potential further
security issues.


Vulnerability overview/description:
-----------------------------------
1) Cross Site Scripting (CVE-2026-4637)
PRTG Security Monitoring reflects the path when trying to acccess a URL which
does not exist. For example, the following URL leads to a 403 forbidden path
error message:

https://<$IP>/not_existing/welcome.htm

```
HTTP/1.1 403 Forbidden Path: /not_existing/

[Error 403: Forbidden Path: /not_existing/]
```

The extension ".htm" is required at the end of the URL. HTML code is not
sanitized in the URL and will be reflected. Unauthorized attackers can
execute arbitrary JavaScript code in the victim's browser in the context
of the attacked PRTG installation.


2) Plaintext Storage of Password (CVE-2026-4638)
A PRTG user can select pre-defined scripts when creating an EXE/Script sensor.
One pre-defined VBScript takes two integers as arguments and returns their
product (e.g. arg1=7 arg2=7, result=49). cscript.exe generally returns
an error if calculating strings. The error contains the string itself.
A documented variable %windowspassword holds the configured domain user
password which can be used as argument for the VBScript and thus gets
reflected as error when trying to run the script.

The PRTG user must not be a read-only user and sensor creation needs to be
allowed (default).


Proof of concept:
-----------------
1) Cross Site Scripting (CVE-2026-4637)
The following URL can be used as a proof of concept reflecting back the
victim's session cookie:

https://<$IP>/<script>alert(document.cookie)</script>/welcome.htm

Since the HttpOnly flag is not set, the cookie will be reflected if a
victim has a session and opens the URL.

```
HTTP/1.1 403 Forbidden Path: /<script>alert(document.cookie)</script>/

[Error 403: Forbidden Path: /<script>alert(document.cookie)</script>/]
```

2) Plaintext Storage of Password (CVE-2026-4638)
The following steps can be performed to reflect the configured domain user
password:

- Create a new sensor EXE/Script
- Select 'Demo VBScript - Multiplies two integers(2 parameters).vbs'
- Use parameter value: '%windowspassword %windowspassword'
- Save
- Click on the refresh symbol to execute the script
- The cscript error in the red paragraph shows the plaintext password

Output:
```
Response not well-formed: "(C:\Program Files (x86)\PRTG Network Monitor\
custom sensors\EXE\Demo VBScript - Multiplies two integers(2 parameters).vbs(6, 1)
Microsoft VBScript runtime error: Type mismatch: '[string: "asdfQWER1234!"]' )"
(code: PE132)
```

Vulnerable / tested versions:
-----------------------------
The following version has been tested which was the latest version available
at the time of the test:
* 25.4.114.1032+

According to the vendor, versions before 26.2.120.1449 are affected.


Vendor contact timeline:
------------------------
2026-01-29: Contacting vendor throughsecurity () paessler com
2026-01-29: Automatic reply that message was received; no further response.
2026-02-09: Following up again, asking for PGP keys.
2026-02-09: Vendor sends PGP key fingerprint, but public PGP key is missing.
2026-02-10: Vendor sends link to PGP key on their website.
            Sending encrypted advisory to vendor.
2026-02-11: Vendor confirms receipt of advisory and starts internal review.
2026-03-05: Asking for a status update.
2026-03-06: Vendor responded with update for coming week.
2026-03-10: Another vendor contact responds to our initial email from 29th
            January.
2026-03-11: Clarifying that it is the same report and vendor investigation
            is already ongoing.
2026-03-23: Vendor stated that the fix will be released in May 27.
2026-03-23: Reserved CVE numbers and communicated them to the vendor.
2026-05-29: Vendor needs to postpone release to 9th July instead of 18th June.
2026-06-03: Vendor fixes issues in version 26.2.120.1449.
2026-06-08: Confirming new release date.
2026-07-02: Vendor drafts communication for customers for the release on 9th July.
2026-07-15: Vendor provides their own security advisory.
2026-07-21: Informing vendor regarding publication delay on our side.
2026-08-12: We will inform vendor regarding release date.
2026-09-23: Planned release for 24th September.
2026-09-24: Public release of security advisory.


Solution:
---------
The vendor provides a patched version 26.2.120.1449 which can be downloaded
from the following URL:

https://www.paessler.com/de/download/

Vendor security advisory:
https://paessler.freshdesk.com/en/support/solutions/articles/76000088640


Workaround:
-----------
None


Advisory URL:
-------------
https://sec-consult.com/vulnerability-lab/


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

SEC Consult Vulnerability Lab
An integrated part of SEC Consult, an Atos business
Europe | Asia

About SEC Consult Vulnerability Lab
The SEC Consult Vulnerability Lab is an integrated part of SEC Consult, an
Atos business. It ensures the continued knowledge gain of SEC Consult in the
field of network and application security to stay ahead of the attacker. The
SEC Consult Vulnerability Lab supports high-quality penetration testing and
the evaluation of new offensive and defensive technologies for our customers.
Hence our customers obtain the most current information about vulnerabilities
and valid recommendation about the risk profile of new technologies.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Interested to work with the experts of SEC Consult?
Send us your applicationhttps://sec-consult.com/career/

Interested in improving your cyber security with the experts of SEC Consult?
Contact our local officeshttps://sec-consult.com/contact/
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Mail: security-research at sec-consult dot com
Web:https://www.sec-consult.com
Blog:http://blog.sec-consult.com
X:https://x.com/sec_consult

EOF J. Kruchem, S. Michlits / @2026

Attachment: smime.p7s
Description: S/MIME Cryptographic Signature

_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: https://seclists.org/fulldisclosure/

Current thread:

  • SEC Consult SA-20260924-0 :: Multiple Vulnerabilities in Paessler PRTG Network Monitor #CVE-2026-4637 #CVE-2026-4638 SEC Consult Vulnerability Lab via Fulldisclosure (Oct 06)

文章来源: https://seclists.org/fulldisclosure/2026/Oct/0
如有侵权请联系:admin#unsafe.sh