PT-2026-97781 · Paessler · Prtg Network Monitor
CVE-2026-4638
·
Published
2026-09-24
·
Updated
2026-09-25
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
PRTG Network Monitor versions prior to 26.2.120.1449
Description
A demo EXE/Script sensor uses
cscript.exe to multiply two integer parameters. When a non-numeric value is provided instead of an integer, cscript.exe triggers a 'Type mismatch' runtime error that displays the input value in plaintext. Because the placeholder variable %windowspassword resolves to the configured Windows or domain password used by the software, a user with permissions to create sensors can pass this variable as an argument to the demo VBScript sensor to reveal the plaintext password in the error output.Recommendations
Update to version 26.2.120.1449 or later.
Fix
Generation of Error Message Containing Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Prtg Network Monitor