ADV-2026-016 - Insufficiently Protected Credentials in Netwrix 1Secure

Executive Summary

A vulnerability was identified in Netwrix 1Secure Cloud Agent which may expose the password of the PingCastle Active Directory service account to third-party systems that monitor processes on the Cloud Agent server. This may allow an attacker to gain unauthorized access to the Active Directory via the service account credentials.

Netwrix is unaware of any evidence of active exploitation of this vulnerability. All Netwrix 1Secure customers are advised to update the Cloud Agent as soon as possible.

Vulnerability

Title Affected Component Affected Versions CVSS 4.0 Score CVSS 3.1 Score (Base / Temporal) Description
Insufficiently Protected Credentials Netwrix 1Secure Cloud Agent >=2.4.1105.0, <2.5.1196.0 8.5 9.1 / 8.7 A vulnerability was identified in Netwrix 1Secure Cloud Agent which may expose the password of the PingCastle Active Directory service account to third-party systems that monitor processes on the Cloud Agent server. This may allow an attacker to gain unauthorized access to the Active Directory via the service account credentials.

Exploitability

Factors such as whether details about the vulnerability are publicly known, whether an exploit is readily available, or whether adversaries are actively exploiting the vulnerability are valuable in making risk-based judgments about urgency and priority; customers should use the information below in making those decisions.

Title Publicly known? Exploit available? Actively exploited?
Insufficiently Protected Credentials No No No

Solution

All Netwrix 1Secure customers are advised to update the Netwrix 1Secure Cloud Agent to version 2.5.1196.0 or later as soon as possible.

Customers are advised to rotate the credentials of the account used for PingCastle scanning in 1Secure.

Visit Updating Netwrix Cloud Agent for information on how to update the Cloud Agent.

Please contact the Netwrix technical support team should you need assistance.

Official Fixes

Updated software has been released containing an official fix for the vulnerability as indicated in the table below.

Product Release Version
Netwrix 1Secure Cloud Agent 2.5.1196.0

FAQ

  1. How do I update the Netwrix 1Secure Cloud Agent?

    See the Netwrix 1Secure documentation for instructions on updating the Cloud Agent.

Revisions

Updates to this advisory may be made as necessary. Information about each change will be published in the table below.

Revision Date Description
1 2026-08-28T12:00:00Z First published

Disclaimer

The information and materials included in or linked to this Security Advisory are provided on an “as-is” basis and without warranty of any kind, and we disclaim all representations and warranties of any kind, whether express or implied, including warranties of merchantability and fitness for a particular use. You acknowledge and agree that your use of the information and materials included in or linked to this Security Advisory are at your own risk.