Description
A directory traversal was identified in Paessler PRTG before 23.4.88.1429 that made it possible to read local files.
Published: 2026-09-14
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Confidentiality breach via local file disclosure
Action: Apply Patch
AI Analysis

Impact

A directory traversal flaw in Paessler PRTG Network Monitor (CWE-23) allows an attacker to read arbitrary files on the host system. By manipulating path parameters in HTTP requests, an attacker can request files outside the intended directory structure, exposing sensitive configuration data, credentials, or other confidential artifacts. The compromise is limited to information disclosure; there is no evidence that the flaw changes system state or provides execution capabilities.

Affected Systems

The vulnerability affects all releases of Paessler PRTG Network Monitor that are older than version 23.4.88.1429. Any installation running a pre‑patch version within the 23.4 series or earlier is susceptible to the directory traversal attack.

Risk and Exploitability

The flaw is rated with a CVSS score of 8.6, indicating high severity. EPSS score is <1%, and the issue is not listed in the CISA KEV catalog, suggesting no widely used or publicly disclosed exploit at this time. The likely attack vector requires network access to the PRTG web interface; the representation of this vector is inferred from the nature of the directory traversal vulnerability, as the official description does not explicitly specify the attacker’s required conditions.

Generated by OpenCVE AI on September 15, 2026 at 16:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade PRTG Network Monitor to version 23.4.88.1429 or later, which removes the directory traversal bug.
  • If an upgrade cannot be performed immediately, configure the web server or an upstream firewall to reject requests containing directory traversal sequences such as "../" before they reach the application.
  • Implement log monitoring to detect attempts to access system files via suspicious URLs and investigate any anomalies promptly.

Generated by OpenCVE AI on September 15, 2026 at 16:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Title Directory Traversal Vulnerability in Paessler PRTG Network Monitor

Mon, 14 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
Title Local File Disclosure via Directory Traversal in PRTG Network Monitor

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Title Local File Disclosure via Directory Traversal in PRTG Network Monitor

Mon, 14 Sep 2026 05:45:00 +0000

Type Values Removed Values Added
Description A directory traversal was identified in Paessler PRTG before 23.4.88.1429 that made it possible to read local files.
First Time appeared Paessler
Paessler prtg Network Monitor
Weaknesses CWE-23
CPEs cpe:2.3:a:paessler:prtg_network_monitor:*:*:*:*:*:*:*:*
Vendors & Products Paessler
Paessler prtg Network Monitor
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Paessler Prtg Network Monitor
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-14T16:15:05.924Z

Reserved: 2023-10-14T00:00:00.000Z

Link: CVE-2023-45858

cve-icon Vulnrichment

Updated: 2026-09-14T16:14:59.136Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T06:16:54.357

Modified: 2026-09-22T19:56:19.073

Link: CVE-2023-45858

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T16:15:15Z

Weaknesses
  • CWE-23

    Relative Path Traversal