Executive Summary
A vulnerability was identified in Netwrix 1Secure Cloud Agent which may expose the password of the PingCastle Active Directory service account to third-party systems that monitor processes on the Cloud Agent server. This may allow an attacker to gain unauthorized access to the Active Directory via the service account credentials.
Netwrix is unaware of any evidence of active exploitation of this vulnerability. All Netwrix 1Secure customers are advised to update the Cloud Agent as soon as possible.
Vulnerability
| Title | Affected Component | Affected Versions | CVSS 4.0 Score | CVSS 3.1 Score (Base / Temporal) | Description |
|---|---|---|---|---|---|
| Insufficiently Protected Credentials | Netwrix 1Secure Cloud Agent | >=2.4.1105.0, <2.5.1196.0 | 8.5 | 9.1 / 8.7 | A vulnerability was identified in Netwrix 1Secure Cloud Agent which may expose the password of the PingCastle Active Directory service account to third-party systems that monitor processes on the Cloud Agent server. This may allow an attacker to gain unauthorized access to the Active Directory via the service account credentials. |
Exploitability
Factors such as whether details about the vulnerability are publicly known, whether an exploit is readily available, or whether adversaries are actively exploiting the vulnerability are valuable in making risk-based judgments about urgency and priority; customers should use the information below in making those decisions.
| Title | Publicly known? | Exploit available? | Actively exploited? |
|---|---|---|---|
| Insufficiently Protected Credentials | No | No | No |
Solution
All Netwrix 1Secure customers are advised to update the Netwrix 1Secure Cloud Agent to version 2.5.1196.0 or later as soon as possible.
Customers are advised to rotate the credentials of the account used for PingCastle scanning in 1Secure.
Visit Updating Netwrix Cloud Agent for information on how to update the Cloud Agent.
Please contact the Netwrix technical support team should you need assistance.
Official Fixes
Updated software has been released containing an official fix for the vulnerability as indicated in the table below.
| Product | Release Version |
|---|---|
| Netwrix 1Secure Cloud Agent | 2.5.1196.0 |
FAQ
-
How do I update the Netwrix 1Secure Cloud Agent?
See the Netwrix 1Secure documentation for instructions on updating the Cloud Agent.
Revisions
Updates to this advisory may be made as necessary. Information about each change will be published in the table below.
| Revision | Date | Description |
|---|---|---|
| 1 | 2026-08-28T12:00:00Z | First published |
Disclaimer
The information and materials included in or linked to this Security Advisory are provided on an “as-is” basis and without warranty of any kind, and we disclaim all representations and warranties of any kind, whether express or implied, including warranties of merchantability and fitness for a particular use. You acknowledge and agree that your use of the information and materials included in or linked to this Security Advisory are at your own risk.