Reflected Cross-Site Scripting Vulnerability in Paessler PRTG Network Monitor
CVE-2026-4637

5.1MEDIUM

Key Information:

Vendor
CVE Published:
24 September 2026

What is CVE-2026-4637?

A reflected Cross-Site Scripting (XSS) vulnerability exists in Paessler PRTG Network Monitor prior to version 26.2.120.1449. When users request non-existent resources with a '.htm' extension, the application returns an error page that includes the requested URL path without proper output encoding or sanitization. Attackers can exploit this by crafting malicious URLs that execute arbitrary JavaScript when opened by a victim with an active PRTG session. As the session cookie lacks protection from the HttpOnly attribute, successful exploitation risks session hijacking by allowing attackers to read and exfiltrate sensitive session information.

Affected Version(s)

PRTG Network Monitor 0 < 26.2.120.1449

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

J. Kruchem, SEC Consult Vulnerability Lab
S. Michlits, SEC Consult Vulnerability Lab
.