PT-2026-97779 · Paessler · Prtg Network Monitor
CVE-2026-4637
·
Published
2026-09-24
·
Updated
2026-09-25
CVSS v4.0
5.1
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Paessler PRTG Network Monitor versions prior to 26.2.120.1449
Description
A reflected Cross-Site Scripting (XSS) issue exists where the web interface returns an HTTP 403 Forbidden Path error page when a request is made for a non-existent resource ending in
.htm. The application echoes the requested URL path into the HTML response body without proper output encoding or sanitization. An unauthenticated remote attacker can craft a URL containing an HTML/JavaScript payload in the path. If a victim with an active session opens this link, arbitrary JavaScript is executed in the security context of the web interface. Since the session cookie lacks the HttpOnly attribute—a security flag that prevents client-side scripts from accessing the cookie—attackers can exfiltrate the session cookie to hijack the session. Approximately 73,800 instances are identified globally.Recommendations
Update to version 26.2.120.1449.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Prtg Network Monitor