Two PRTG Bugs, One Release: The 26.2.120.1449 Fix for CVE-2026-4637 and CVE-2026-4638
SEC Consult Vulnerability Lab disclosed two issues in Paessler PRTG Network Monitor on 24 September 2026. Paessler corrected both in build 26.2.120.1449. Reading them together shows what a monitoring server exposes when an error path and an error message both carry too much information.
Vulnerability overview
CVE-2026-4637 covers the scripting defect and is classed as CWE-79 with a CVSS 4.0 base score of 5.1 in NVD. CVE-2026-4638 covers the disclosure and is classed as CWE-209 with a CVSS 4.0 base score of 7.1. CERT-Bund catalogues both in WID-SEC-2026-3565 with a CVSS 3.1 base score of 8.1, reflecting the pair rather than either issue alone.
Mechanism and exploitation conditions
Both problems are error-handling problems, which is why they shipped in the same advisory. In the first, PRTG returns HTTP 403 for a missing path ending in .htm and echoes that path into the response body without encoding. The echo is enough for a browser to execute attacker markup in the PRTG origin, given a logged-in operator who opens the crafted link. The session cookie lacks HttpOnly, so the script can read it.
In the second, the interface displays what a failed script returns. A demo sensor multiplies two integers through cscript.exe and errors on non-numeric input, quoting it back. Because %windowspassword resolves to the configured Windows or domain password, using it as the argument puts that password into the error message. A non-read-only PRTG user with sensor-creation rights, which is the default, can produce it.
Impact
The first flaw yields an operator session, and therefore access to the monitoring configuration and the reach of that account. The second yields a password for the Windows or domain account PRTG uses against monitored hosts. Neither needs elevated rights inside PRTG, and together they cover both the session layer and the credential layer of the same platform.
The second also complicates remediation. Updating the software stops the message from appearing, but the disclosed password stays valid until it is changed, so the incident response extends past the patch window.
Affected products and scope
The affected range is PRTG Network Monitor before 26.2.120.1449, and the fix is that build. SEC Consult tested 25.4.114.1032. Their published timeline records the assessment beginning on 29 January 2026, the fix on 3 June 2026 and public release on 24 September 2026.
Exposure context
On 25 September 2026, ZoomEye returned 73,798 assets for the query app="PRTG" with sub_type all and none for vul.cve="CVE-2026-4638". The first number describes fingerprint matches across the internet; it is not a vulnerability count, since the query cannot see installed builds or account permissions. The second records that ZoomEye had not indexed this CVE identifier.
Remediation and mitigations
Upgrade to 26.2.120.1449 or later, using https://www.paessler.com/de/download/ for the build and https://paessler.freshdesk.com/en/support/solutions/articles/76000088640 for the vendor statement. No workaround appears in the SEC Consult advisory at https://sec-consult.com/vulnerability-lab/advisory/multiple-vulnerabilities-in-paessler-prtg-network-monitor/.
Treat the exposed credential as the follow-up. Rotating the Windows or domain password PRTG uses, and reviewing what that account can reach, addresses the part of the impact a software update cannot undo.
References
- SEC Consult advisory: https://sec-consult.com/vulnerability-lab/advisory/multiple-vulnerabilities-in-paessler-prtg-network-monitor/
- Paessler vendor advisory: https://paessler.freshdesk.com/en/support/solutions/articles/76000088640
- Paessler download page: https://www.paessler.com/de/download/
- NVD CVE-2026-4637: https://nvd.nist.gov/vuln/detail/CVE-2026-4637
- NVD CVE-2026-4638: https://nvd.nist.gov/vuln/detail/CVE-2026-4638
- CERT-Bund WID-SEC-2026-3565: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3565
- ZoomEye query app="PRTG": https://www.zoomeye.ai/searchResult?q=YXBwPSJQUlRHIg%3D%3D
Top comments (0)