Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-4637— Reflected Cross-Site Scripting via URL Path in Paessler PRTG Network Monitor

Quick assessment

Affected
Paessler GmbH PRTG Network Monitor
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Paessler PRTG Network Monitor 版本低于 26.2.120.1449 的版本中,存在一个反射型跨站脚本(XSS)漏洞。当向一个以“.htm”结尾但不存在的资源发送请求时,Web 界面会返回一个 HTTP 403 “Forbidden Path”错误页面,该页面会将请求的 URL 路径直接回显到 HTML 响应体中,且未进行适当的输出编码或清理。 未认证的远程攻击者可以构造一个在路径中包含 HTML/JavaScript 恶意载荷的 URL(例如 https:////welcome.h

CVSS 5.1 · Medium EPSS 0.55% · P44
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-4637

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Reflected Cross-Site Scripting via URL Path in Paessler PRTG Network Monitor
Source: CVE Program / CVE List V5
Vulnerability Description
Paessler PRTG Network Monitor before version 26.2.120.1449 is affected by a reflected Cross-Site Scripting (XSS) vulnerability. When a request is made for a non-existent resource ending in \".htm\", the web interface returns an HTTP 403 \"Forbidden Path\" error page that echoes the requested URL path into the HTML response body without proper output encoding or sanitization. An unauthenticated, remote attacker can craft a URL containing an HTML/JavaScript payload in the path (e.g. https:////welcome.htm) and, once a victim with an active PRTG session opens the crafted link, execute arbitrary JavaScript in the security context of the PRTG web interface. Because the PRTG session cookie is not protected with the HttpOnly attribute, successful exploitation allows the attacker to read and exfiltrate the victim's session cookie, potentially leading to session hijacking.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Paessler GmbH PRTG Network Monitor 0 ~ 26.2.120.1449 -

II. Public POCs for CVE-2026-4637

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-4637

请登录查看更多情报信息。

Vendor Pages for CVE-2026-4637 (1)

Other References for CVE-2026-4637 (3)

IV. Related Vulnerabilities

V. Comments for CVE-2026-4637

No comments yet


Leave a comment