๐Ÿ” CVE Alert

CVE-2026-4638

UNKNOWN 0.0

Plaintext Password Disclosure via VBScript Sensor Error Message in Paessler PRTG Network Monitor

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

PRTG Network Monitor before version 26.2.120.1449 ships a demo EXE/Script sensor that multiplies two integer parameters using cscript.exe. If a non-numeric value is passed instead, cscript.exe raises a 'Type mismatch' runtime error that includes the offending parameter value in plaintext. PRTG provides a documented placeholder variable, %windowspassword, which resolves to the configured Windows/domain password used by PRTG and can be passed as a sensor parameter.ย  Any PRTG user who is not restricted to read-only access and is permitted to create sensors (the default for non-read-only users) can pass %windowspassword as an argument to the demo VBScript sensor, triggering the type-mismatch error and causing PRTG to display the plaintext password in the sensor's error output.

CWE CWE-209
Vendor paessler gmbh
Product prtg network monitor
Published Sep 24, 2026
Last Updated Sep 24, 2026
Stay Ahead of the Next One

Get instant alerts for paessler gmbh prtg network monitor

Be the first to know when new unknown vulnerabilities affecting paessler gmbh prtg network monitor are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Paessler GmbH / PRTG Network Monitor
0 < 26.2.120.1449

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
r.sec-consult.com: https://r.sec-consult.com/paessler paessler.freshdesk.com: https://paessler.freshdesk.com/en/support/solutions/articles/76000088640 paessler.com: https://www.paessler.com/de/download/ paessler.com: https://www.paessler.com/prtg/prtg-network-monitor

Credits

J. Kruchem, SEC Consult Vulnerability Lab S. Michlits, SEC Consult Vulnerability Lab