Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

SEC Consult SA-20260924-0 :: Multiple Vulnerabilities in Paessler PRTG Network Monitor #CVE-2026-4637 #CVE-2026-4638

Дата публикации: 06-10-2026 17:44:41

Posted by SEC Consult Vulnerability Lab via Fulldisclosure on Oct 06SEC Consult Vulnerability Lab Security Advisory < 20260924-0 >
=======================================================================
title: Multiple Vulnerabilities
product: Paessler PRTG Network Monitor
vulnerable version: <26.2.120.1449
      fixed version: 26.2.120.1449
         CVE number: CVE-2026-4637, CVE-2026-4638
             impact: high
homepage:...


Основное содержимое страницы с новостью.

fulldisclosure logo Full Disclosure mailing list archives
From: SEC Consult Vulnerability Lab via Fulldisclosure <fulldisclosure () seclists org>
Date: Thu, 1 Oct 2026 10:57:56 +0000

SEC Consult Vulnerability Lab Security Advisory < 20260924-0 >
=======================================================================
              title: Multiple Vulnerabilities
            product: Paessler PRTG Network Monitor
 vulnerable version: <26.2.120.1449
      fixed version: 26.2.120.1449
         CVE number: CVE-2026-4637, CVE-2026-4638
             impact: high
           homepage:https://www.paessler.com/prtg/prtg-network-monitor
              found: 2026-01-29
                 by: J. Kruchem (Office Vienna)
                     S. Michlits (Office Vienna)
                     SEC Consult Vulnerability Lab

                     An integrated part of SEC Consult, an Atos business
                     Europe | Asia

                     https://www.sec-consult.com

=======================================================================

Vendor description:
-------------------
"We provide industry-leading monitoring solutions for businesses of all
sizes, from SMBs to large enterprises. In collaboration with trusted
partners, we address the challenges of ever-evolving infrastructures,
ensuring that businesses can operate without disruption.

Source:https://www.paessler.com/company/about-us


Business recommendation:
------------------------
The vendor provides a patch which should be installed immediately.

SEC Consult highly recommends to perform a thorough security review of the product
conducted by security professionals to identify and resolve potential further
security issues.


Vulnerability overview/description:
-----------------------------------
1) Cross Site Scripting (CVE-2026-4637)
PRTG Security Monitoring reflects the path when trying to acccess a URL which
does not exist. For example, the following URL leads to a 403 forbidden path
error message:

https://<$IP>/not_existing/welcome.htm

```
HTTP/1.1 403 Forbidden Path: /not_existing/

[Error 403: Forbidden Path: /not_existing/]
```

The extension ".htm" is required at the end of the URL. HTML code is not
sanitized in the URL and will be reflected. Unauthorized attackers can
execute arbitrary JavaScript code in the victim's browser in the context
of the attacked PRTG installation.


2) Plaintext Storage of Password (CVE-2026-4638)
A PRTG user can select pre-defined scripts when creating an EXE/Script sensor.
One pre-defined VBScript takes two integers as arguments and returns their
product (e.g. arg1=7 arg2=7, result=49). cscript.exe generally returns
an error if calculating strings. The error contains the string itself.
A documented variable %windowspassword holds the configured domain user
password which can be used as argument for the VBScript and thus gets
reflected as error when trying to run the script.

The PRTG user must not be a read-only user and sensor creation needs to be
allowed (default).


Proof of concept:
-----------------
1) Cross Site Scripting (CVE-2026-4637)
The following URL can be used as a proof of concept reflecting back the
victim's session cookie:

https://<$IP>/<script>alert(document.cookie)</script>/welcome.htm

Since the HttpOnly flag is not set, the cookie will be reflected if a
victim has a session and opens the URL.

```
HTTP/1.1 403 Forbidden Path: /<script>alert(document.cookie)</script>/

[Error 403: Forbidden Path: /<script>alert(document.cookie)</script>/]
```

2) Plaintext Storage of Password (CVE-2026-4638)
The following steps can be performed to reflect the configured domain user
password:

- Create a new sensor EXE/Script
- Select 'Demo VBScript - Multiplies two integers(2 parameters).vbs'
- Use parameter value: '%windowspassword %windowspassword'
- Save
- Click on the refresh symbol to execute the script
- The cscript error in the red paragraph shows the plaintext password

Output:
```
Response not well-formed: "(C:\Program Files (x86)\PRTG Network Monitor\
custom sensors\EXE\Demo VBScript - Multiplies two integers(2 parameters).vbs(6, 1)
Microsoft VBScript runtime error: Type mismatch: '[string: "asdfQWER1234!"]' )"
(code: PE132)
```

Vulnerable / tested versions:
-----------------------------
The following version has been tested which was the latest version available
at the time of the test:
* 25.4.114.1032+

According to the vendor, versions before 26.2.120.1449 are affected.


Vendor contact timeline:
------------------------
2026-01-29: Contacting vendor throughsecurity () paessler com
2026-01-29: Automatic reply that message was received; no further response.
2026-02-09: Following up again, asking for PGP keys.
2026-02-09: Vendor sends PGP key fingerprint, but public PGP key is missing.
2026-02-10: Vendor sends link to PGP key on their website.
            Sending encrypted advisory to vendor.
2026-02-11: Vendor confirms receipt of advisory and starts internal review.
2026-03-05: Asking for a status update.
2026-03-06: Vendor responded with update for coming week.
2026-03-10: Another vendor contact responds to our initial email from 29th
            January.
2026-03-11: Clarifying that it is the same report and vendor investigation
            is already ongoing.
2026-03-23: Vendor stated that the fix will be released in May 27.
2026-03-23: Reserved CVE numbers and communicated them to the vendor.
2026-05-29: Vendor needs to postpone release to 9th July instead of 18th June.
2026-06-03: Vendor fixes issues in version 26.2.120.1449.
2026-06-08: Confirming new release date.
2026-07-02: Vendor drafts communication for customers for the release on 9th July.
2026-07-15: Vendor provides their own security advisory.
2026-07-21: Informing vendor regarding publication delay on our side.
2026-08-12: We will inform vendor regarding release date.
2026-09-23: Planned release for 24th September.
2026-09-24: Public release of security advisory.


Solution:
---------
The vendor provides a patched version 26.2.120.1449 which can be downloaded
from the following URL:

https://www.paessler.com/de/download/

Vendor security advisory:
https://paessler.freshdesk.com/en/support/solutions/articles/76000088640


Workaround:
-----------
None


Advisory URL:
-------------
https://sec-consult.com/vulnerability-lab/


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

SEC Consult Vulnerability Lab
An integrated part of SEC Consult, an Atos business
Europe | Asia

About SEC Consult Vulnerability Lab
The SEC Consult Vulnerability Lab is an integrated part of SEC Consult, an
Atos business. It ensures the continued knowledge gain of SEC Consult in the
field of network and application security to stay ahead of the attacker. The
SEC Consult Vulnerability Lab supports high-quality penetration testing and
the evaluation of new offensive and defensive technologies for our customers.
Hence our customers obtain the most current information about vulnerabilities
and valid recommendation about the risk profile of new technologies.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Interested to work with the experts of SEC Consult?
Send us your applicationhttps://sec-consult.com/career/

Interested in improving your cyber security with the experts of SEC Consult?
Contact our local officeshttps://sec-consult.com/contact/
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Mail: security-research at sec-consult dot com
Web:https://www.sec-consult.com
Blog:http://blog.sec-consult.com
X:https://x.com/sec_consult

EOF J. Kruchem, S. Michlits / @2026

Attachment: smime.p7s
Description: S/MIME Cryptographic Signature

_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: https://seclists.org/fulldisclosure/

Current thread:
  • SEC Consult SA-20260924-0 :: Multiple Vulnerabilities in Paessler PRTG Network Monitor #CVE-2026-4637 #CVE-2026-4638 SEC Consult Vulnerability Lab via Fulldisclosure (Oct 06)

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution08.3930-09-2026
2SEC Consult Research 20261001 :: Arbitrary Email sender spoofing in Apple iCloud mail05.4106-10-2026
3Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT07.930-09-2026
4[0day-rubbish] Advantech WebAccess Node 9.2.3 unauthenticated CrystalRpt.aspx file upload and path traversal to code execution in w3wp.exe (9.8)010.4106-10-2026
5[0day-rubbish] Circutor LineEds 24.11.14-r0 unauthenticated pwrstudio events.xml shellExecute command injection (9.8)011.6706-10-2026
6CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally07.6328-09-2026
7[0day-rubbish] IPConfigure Orchid VMS 26.3.0 authenticated DNF repository GPG-key property command injection to root (7.2)09.0406-10-2026
8Sicherheitspatch gegen Schadcode repariert SolarWinds Observability Self-Hosted024.8224-09-2026
9Citrix discloses third actively exploited NetScaler zero-day in less than a week09.5705-10-2026

Классификация: Пресс-релизы. Схожих патентов: 0. Схожих новостей: 9. Тональность: 0. Информативность: 7.78. Источник: seclists.org.