Integer Parameter Type Mismatch in PRTG Network Monitor
CVE-2026-4638
7.1HIGH
What is CVE-2026-4638?
In PRTG Network Monitor prior to version 26.2.120.1449, a demo EXE/Script sensor that multiplies two integer parameters is vulnerable to a type mismatch error. If a non-numeric value is submitted, the cscript.exe raises a runtime error displaying the invalid parameter in plaintext. Notably, the documented placeholder variable %windowspassword, which resolves to the Windows/domain password configured for PRTG, can be exploited by users with sensor creation permissions to trigger this vulnerability, revealing sensitive information in an error output.
Affected Version(s)
PRTG Network Monitor 0 < 26.2.120.1449
References
CVSS V4
Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
J. Kruchem, SEC Consult Vulnerability Lab
S. Michlits, SEC Consult Vulnerability Lab
