PT-2026-97779 · Paessler · Prtg Network Monitor

CVE-2026-4637

·

Published

2026-09-24

·

Updated

2026-09-25

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Paessler PRTG Network Monitor versions prior to 26.2.120.1449
Description A reflected Cross-Site Scripting (XSS) issue exists where the web interface returns an HTTP 403 Forbidden Path error page when a request is made for a non-existent resource ending in .htm. The application echoes the requested URL path into the HTML response body without proper output encoding or sanitization. An unauthenticated remote attacker can craft a URL containing an HTML/JavaScript payload in the path. If a victim with an active session opens this link, arbitrary JavaScript is executed in the security context of the web interface. Since the session cookie lacks the HttpOnly attribute—a security flag that prevents client-side scripts from accessing the cookie—attackers can exfiltrate the session cookie to hijack the session. Approximately 73,800 instances are identified globally.
Recommendations Update to version 26.2.120.1449.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-4637

Affected Products

Prtg Network Monitor