Executive Summary
Internal security review identified several vulnerabilities in the Netwrix Endpoint Protector Server. Depending on the vulnerability, these issues could allow an administrator to influence the behavior of underlying database queries, run a malicious script within another administrator’s browser session, achieve privileged arbitrary code execution on the appliance, access data belonging to other departments, or compromise downstream integrated services and data.
While Netwrix is unaware of any current exploitation of these vulnerabilities, all Netwrix Endpoint Protector customers are advised to apply the available update immediately.
Vulnerability
| Title | Affected Component | Affected Versions | CVSS 4.0 Score | CVSS 3.1 Score (Base / Temporal) | Description |
|---|---|---|---|---|---|
| Use of Hard-coded Credentials | Endpoint Protector Server | <=2604.0.1.0 | 9.5 | 10.0 / 8.7 | An attacker who obtains access to the appliance image could use sensitive keys or credentials to compromise associated downstream services and data. |
| Improper Neutralization of Special Elements used in a Command | Endpoint Protector Server | <=2604.0.1.0 | 9.4 | 9.1 / 8.3 | Insufficient validation of certain configuration settings may allow an administrator to achieve arbitrary command execution on the appliance with elevated privileges. |
| Use of Hard-coded Cryptographic Key | Endpoint Protector Server | <=2604.0.1.0 | 8.9 | 9.1 / 7.9 | The key used to secure the offline patch feature can be recovered by an administrator, potentially allowing a malicious patch to achieve arbitrary command execution on the appliance with elevated privileges when applied. |
| Improper Control of Generation of Code (‘Code Injection’) | Endpoint Protector Server | <=2604.0.1.0 | 8.9 | 9.1 / 7.9 | Insufficient validation of certain update-related network communications may allow an administrator to achieve arbitrary code execution on the appliance with elevated privileges. |
| Improper Neutralization of Special Elements used in an SQL Command | Endpoint Protector Server | <=2604.0.1.0 | 7.1 | 6.5 / 6.2 | Insufficient validation of inputs used in SQL queries within certain application components may allow an administrator to influence the behavior of underlying database queries. |
| Authorization Bypass Through User-Controlled Key | Endpoint Protector Server | <=2604.0.1.0 | 6.8 | 5.7 / 5.0 | Insufficient authorization checks on certain storage operations may allow an administrator to access or delete files belonging to departments they are not granted access to. |
| Improper Neutralization of Input During Web Page Generation | Endpoint Protector Server | <=2604.0.1.0 | 5.1 | 5.4 / 4.7 | Insufficient validation of stored user-supplied input may have allowed a malicious script to run within another administrator’s browser session. |
Exploitability
Factors such as whether details about the vulnerability are publicly known, whether an exploit is readily available, or whether adversaries are actively exploiting the vulnerability are valuable in making risk-based judgments about urgency and priority; customers should use the information below in making those decisions.
| Title | Publicly known? | Exploit available? | Actively exploited? |
|---|---|---|---|
| Improper Neutralization of Special Elements used in a Command | No | No | No |
| Use of Hard-coded Credentials | No | No | No |
| Use of Hard-coded Cryptographic Key | No | No | No |
| Improper Control of Generation of Code (‘Code Injection’) | No | No | No |
| Improper Neutralization of Special Elements used in an SQL Command | No | No | No |
| Authorization Bypass Through User-Controlled Key | No | No | No |
| Improper Neutralization of Input During Web Page Generation | No | No | No |
Solution
All Netwrix Endpoint Protector customers are advised to update Endpoint Protector to version 2608.0.1.0 or later as soon as possible.
Please contact the Netwrix technical support team should you need assistance.
Official Fixes
Updated software has been released containing an official fix for the vulnerability as indicated in the table below.
| Product | Release Version |
|---|---|
| Netwrix Endpoint Protector | 2608.0.1.0 |
FAQ
-
How do I determine the version of Netwrix Endpoint Protector is in use?
The Netwrix Endpoint Protector server version number can be seen in the lower-right corner of the application window.
-
Are there any configuration changes required after updating?
No additional configuration changes are required. The fixes are automatically applied upon updating to the remediated version.
Revisions
Updates to this advisory may be made as necessary. Information about each change will be published in the table below.
| Revision | Date | Description |
|---|---|---|
| 1 | 2026-09-01T12:00:00Z | First published |
Disclaimer
The information and materials included in or linked to this Security Advisory are provided on an “as-is” basis and without warranty of any kind, and we disclaim all representations and warranties of any kind, whether express or implied, including warranties of merchantability and fitness for a particular use. You acknowledge and agree that your use of the information and materials included in or linked to this Security Advisory are at your own risk.