CVE-2026-4638
— UNSCOREDPublished 2026-09-24 · Updated 2026-09-24
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
PRTG Network Monitor before version 26.2.120.1449 ships a demo EXE/Script sensor that multiplies two integer parameters using cscript.exe. If a non-numeric value is passed instead, cscript.exe raises a 'Type mismatch' runtime error that includes the offending parameter value in plaintext. PRTG provides a documented placeholder variable, %windowspassword, which resolves to the configured Windows/domain password used by PRTG and can be passed as a sensor parameter. Any PRTG user who is not restricted to read-only access and is permitted to create sensors (the default for non-read-only users) can pass %windowspassword as an argument to the demo VBScript sensor, triggering the type-mismatch error and causing PRTG to display the plaintext password in the sensor's error output.
Weaknesses
CWE-209
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- MEDIUMCVE-2025-1350
- MEDIUMCVE-2026-100677PoC
- MEDIUMCVE-2026-1030
- MEDIUMCVE-2026-3626
- MEDIUMCVE-2026-47622PoC
- LOWCVE-2026-4921
- MEDIUMCVE-2026-71461
- LOWCVE-2026-71463
Related by shared AI tags and CWE weakness class. Browse the full archive.