CVE-2026-4637 Details
Description
Paessler PRTG Network Monitor before version 26.2.120.1449 is affected by a reflected Cross-Site Scripting (XSS) vulnerability. When a request is made for a non-existent resource ending in \".htm\", the web interface returns an HTTP 403 \"Forbidden Path\" error page that echoes the requested URL path into the HTML response body without proper output encoding or sanitization. An unauthenticated, remote attacker can craft a URL containing an HTML/JavaScript payload in the path (e.g. https:////welcome.htm) and, once a victim with an active PRTG session opens the crafted link, execute arbitrary JavaScript in the security context of the PRTG web interface. Because the PRTG session cookie is not protected with the HttpOnly attribute, successful exploitation allows the attacker to read and exfiltrate the victim's session cookie, potentially leading to session hijacking.
A reflected cross-site scripting vulnerability has been identified in Paessler PRTG Network Monitor versions prior to 26.2.120.1449. This vulnerability occurs when the web interface returns a '403 Forbidden Path' error page for non-existent resources ending in '.htm'. The error page improperly sanitizes the echoed URL, allowing an unauthenticated, remote attacker to inject HTML/JavaScript payloads. When a victim with an active PRTG session clicks the crafted link, the injected script is executed in the context of the PRTG web interface. Exploitation is facilitated by the absence of the HttpOnly attribute on the PRTG session cookie, enabling the attacker to steal the cookie and potentially hijack the victim's session.
Users are advised to upgrade to PRTG version 26.2.120.1449, which is available for download from the Paessler website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 24, 2026CISA-ADP
Assessed Sep 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://sec-consult.com/vulnerability-lab/advisory/multiple-vulnerabilities-in-paessler-prtg-network-monitor/ | CISA-ADP | BundleExploitRemedyTechnical Analysis |
| https://paessler.freshdesk.com/en/support/solutions/articles/76000088640 | SEC Consult Vulnerability Lab | AdvisoryBundleRemedyVendor |
| https://r.sec-consult.com/paessler | SEC Consult Vulnerability Lab | BundleExploitRemedyTechnical Analysis |
| https://www.paessler.com/de/download/ | SEC Consult Vulnerability Lab | ProductVendor |
| https://www.paessler.com/prtg/prtg-network-monitor | SEC Consult Vulnerability Lab | ProductVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | SEC Consult Vulnerability Lab |
Affected Products
| Product | Versions |
|---|---|
| Paessler PRTG Network Monitor | < 26.2.120.1449 |
CPE
Remediation
| |
| Paessler PRTG Enterprise Monitor | All versions |
CPE
Remediation
| |
| Paessler PRTG Hosted Monitor | All versions |
CPE
Remediation
| |
| Paessler PRTG UVexplorer | All versions |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 24, 2026 | CVE Modified | CISA-ADP |
| Sep 24, 2026 | New CVE Received | SEC Consult Vulnerability Lab |
Volerion