Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-4638— Plaintext Password Disclosure via VBScript Sensor Error Message in Paessler PRTG Network Monitor

Quick assessment

Affected
Paessler GmbH PRTG Network Monitor
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

PRTG Network Monitor 在 26.2.120.1449 版本之前,提供了一个示例 EXE/脚本传感器(demo EXE/Script sensor),该传感器使用 cscript.exe 执行乘法运算,传入两个整数参数。如果传入的是非数字值,cscript.exe 会引发一个“类型不匹配”(Type mismatch)的运行时错误,并在错误信息中以明文形式显示导致错误的参数值。 PRTG 提供了一个文档记录的占位符变量 %windowspassword,该变量会被解析为 PRTG 配置中使用的 W

CVSS 7.1 · High EPSS 0.27% · P17
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-4638

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Plaintext Password Disclosure via VBScript Sensor Error Message in Paessler PRTG Network Monitor
Source: CVE Program / CVE List V5
Vulnerability Description
PRTG Network Monitor before version 26.2.120.1449 ships a demo EXE/Script sensor that multiplies two integer parameters using cscript.exe. If a non-numeric value is passed instead, cscript.exe raises a 'Type mismatch' runtime error that includes the offending parameter value in plaintext. PRTG provides a documented placeholder variable, %windowspassword, which resolves to the configured Windows/domain password used by PRTG and can be passed as a sensor parameter.  Any PRTG user who is not restricted to read-only access and is permitted to create sensors (the default for non-read-only users) can pass %windowspassword as an argument to the demo VBScript sensor, triggering the type-mismatch error and causing PRTG to display the plaintext password in the sensor's error output.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
通过错误消息导致的信息暴露
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Paessler GmbH PRTG Network Monitor 0 ~ 26.2.120.1449 -

II. Public POCs for CVE-2026-4638

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-4638

请登录查看更多情报信息。

Vendor Pages for CVE-2026-4638 (1)

Other References for CVE-2026-4638 (3)

IV. Related Vulnerabilities

V. Comments for CVE-2026-4638

No comments yet


Leave a comment