Reflected Cross-Site Scripting Vulnerability in Paessler PRTG Network Monitor
CVE-2026-4637
5.1MEDIUM
What is CVE-2026-4637?
A reflected Cross-Site Scripting (XSS) vulnerability exists in Paessler PRTG Network Monitor prior to version 26.2.120.1449. When users request non-existent resources with a '.htm' extension, the application returns an error page that includes the requested URL path without proper output encoding or sanitization. Attackers can exploit this by crafting malicious URLs that execute arbitrary JavaScript when opened by a victim with an active PRTG session. As the session cookie lacks protection from the HttpOnly attribute, successful exploitation risks session hijacking by allowing attackers to read and exfiltrate sensitive session information.
Affected Version(s)
PRTG Network Monitor 0 < 26.2.120.1449
References
CVSS V4
Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
J. Kruchem, SEC Consult Vulnerability Lab
S. Michlits, SEC Consult Vulnerability Lab
