Any PRTG user who is not restricted to read-only access and is permitted to create sensors (the default for non-read-only users) can pass %windowspassword as an argument to the demo VBScript sensor, triggering the type-mismatch error and causing PRTG to display the plaintext password in the sensor's error output.
Metrics
Affected Vendors & Products
No advisories yet.
Solution
Upgrade to Paessler PRTG Network Monitor version 26.2.120.1449 or later.
Workaround
No workaround given by the vendor.
Thu, 24 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 24 Sep 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Paessler
Paessler prtg Network Monitor |
|
| Vendors & Products |
Paessler
Paessler prtg Network Monitor |
Thu, 24 Sep 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PRTG Network Monitor before version 26.2.120.1449 ships a demo EXE/Script sensor that multiplies two integer parameters using cscript.exe. If a non-numeric value is passed instead, cscript.exe raises a 'Type mismatch' runtime error that includes the offending parameter value in plaintext. PRTG provides a documented placeholder variable, %windowspassword, which resolves to the configured Windows/domain password used by PRTG and can be passed as a sensor parameter. Any PRTG user who is not restricted to read-only access and is permitted to create sensors (the default for non-read-only users) can pass %windowspassword as an argument to the demo VBScript sensor, triggering the type-mismatch error and causing PRTG to display the plaintext password in the sensor's error output. | |
| Title | Plaintext Password Disclosure via VBScript Sensor Error Message in Paessler PRTG Network Monitor | |
| Weaknesses | CWE-209 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: SEC-VLab
Published:
Updated: 2026-09-24T12:14:20.861Z
Reserved: 2026-03-23T10:32:11.997Z
Link: CVE-2026-4638
Updated: 2026-09-24T12:14:08.861Z
Status : Deferred
Published: 2026-09-24T11:16:45.953
Modified: 2026-09-24T20:43:32.537
Link: CVE-2026-4638
No data.
OpenCVE Enrichment
Updated: 2026-09-24T13:00:14Z