OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-4638

HIGH · CVSS 7.1 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-09-24 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

PRTG Network Monitor versions prior to 26.2.120.1449 are vulnerable due to a demo EXE/Script sensor that exposes Windows/domain passwords in plaintext through a type mismatch error when non-numeric values are used. This vulnerability allows any non-read-only user with sensor creation permissions to exploit the system and retrieve sensitive information. Organizations using PRTG should prioritize patching this vulnerability to protect against potential credential leakage and unauthorized access.

CVE
CVE-2026-4638
Severity
HIGH
CVSS
7.1
EPSS
0.27%
Windows

Original NVD Description

PRTG Network Monitor before version 26.2.120.1449 ships a demo EXE/Script sensor that multiplies two integer parameters using cscript.exe. If a non-numeric value is passed instead, cscript.exe raises a 'Type mismatch' runtime error that includes the offending parameter value in plaintext. PRTG provides a documented placeholder variable, %windowspassword, which resolves to the configured Windows/domain password used by PRTG and can be passed as a sensor parameter.  Any PRTG user who is not restricted to read-only access and is permitted to create sensors (the default for non-read-only users) can pass %windowspassword as an argument to the demo VBScript sensor, triggering the type-mismatch error and causing PRTG to display the plaintext password in the sensor's error output.