ZeroHour
Vendor

Telerik

0 mentions in 7 days · 2 in 30 days · 2 total · first seen · last

Timeline

Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released

TantoSec published a working exploit chaining a Telerik UI padding oracle to unauthenticated RCE; Progress patched the flaws in July.

TantoSec's Marcio Almeida released a full exploit chain and tooling for the RadAsyncUpload control in Telerik UI for ASP.NET AJAX, turning a padding oracle (CVE-2026-13182) into unauthenticated RCE via an unguarded type-resolution flaw (CVE-2026-13181, CVSS 8.1). Exploitation requires a rendered RadAsyncUpload handler and an explicit non-default encryption key, and took roughly 127,000 oracle requests (about an hour) in lab testing. Versions 2010.1.309 through 2026.2.519 are affected; Progress fixed the chain in 2026.2.708 on July 8, 2026, and no in-the-wild exploitation has been confirmed. A separate RCE chain in RadPersistenceManager and RadDockLayout (CVE-2026-13185, -13186, -13190) was also patched but has no public exploit.

Progress Software security advisory (AV26-875)

Canada's Cyber Centre warns Progress Telerik UI for ASP.NET AJAX before 2026.3.812 is affected by path traversal and upload tampering flaws, urging updates.

The Canadian Centre for Cyber Security issued advisory AV26-875 on September 2, 2026, covering vulnerabilities in Progress Software Telerik UI for ASP.NET AJAX prior to version 2026.3.812. Two flaws are listed: CVE-2026-18672, a path traversal in the Telerik Web Forms RadImageEditor, and CVE-2026-19219, a DialogHandler UploadPaths tampering vulnerability. Administrators are encouraged to review the provided links and apply available updates.

Related CVEs

  • Unauthenticated .NET Deserialization RCE in Progress Telerik UI for ASP.NET AJAX
    CVE-2019-18935 is a .NET deserialization flaw (CWE-502) in the RadAsyncUpload function of Progress Telerik UI for ASP.NET AJAX through version 2019.3.1023. It is triggered when an attacker who knows the Telerik upload encryption keys — most commonly because the earlier flaws CVE-2017-11317 or CVE-2017-11357 exposed them, though keys can be obtained by other means — sends crafted serialized data to RadAsyncUpload, allowing remote code execution without authentication. Successful exploitation gives an attacker arbitrary code execution on the hosting IIS/ASP.NET web server, reflected in the critical 9.8 CVSS score. Any web application built with Telerik UI for ASP.NET AJAX at or below 2019.3.1023 is affected, unless 2019.3.1023 has the non-default hardening setting enabled (as of 2020.1.114 a default setting prevents the exploit). Exploitation is rampant in the wild: the flaw was added to CISA KEV on 2021-11-03 with known ransomware use, carries a 99.7% EPSS probability of exploitation, has multiple public exploits (Bishop Fox, RAU_crypto, noperator), and has been used by multiple threat groups — including ransomware and government-linked actors — to breach organizations including a U.S. federal agency.
    · Telerik (Progress) UI for ASP.NET AJAX All versions through 2019.3.1023 (RadAsyncUpload exploitable when encryption keys are known; 2019.3.1023 requires a non-default setting to prevent exploitation; KEV ransomware PoC ×4large
  • In Progress® Telerik® UI for AJAX prior to v2026.2.708, applications using cookie-based storage in RadPersistenceManager or RadDockLayout deserialize attacker-c
    In Progress® Telerik® UI for AJAX prior to v2026.2.708, applications using cookie-based storage in RadPersistenceManager or RadDockLayout deserialize attacker-controlled cookie content, allowing unauthenticated remote code execution.
    · progress telerik ui for asp.net ajax
  • Potential RCE in Progress Telerik UI for ASP.NET AJAX via dialog parameter tampering
    Progress Telerik UI for ASP.NET AJAX before v2026.3.812 provides insufficient integrity protection (CWE-345) on the dialog request parameters used by the RadEditor file browser, allowing those parameters to be altered. To exploit it, a network attacker must first have obtained certain application encryption key material used to protect the dialog parameters, which drives the high attack complexity; no privileges or user interaction are required. With tampered parameters, the attacker can control which folders the file browser reads from, writes to, and uploads into, enabling arbitrary file uploads (CWE-434) and potentially remote code execution by writing attacker-controlled files into sensitive or web-executable locations. Any web application built with Telerik UI for ASP.NET AJAX in versions prior to 2026.3.812 is affected. Exploitation has not been observed: there is no public proof-of-concept, the flaw is not in the CISA KEV catalog, and EPSS assigns only a 0.2% probability of exploitation within 30 days.
    · Progress Software Telerik UI for ASP.NET AJAX (RadEditor file browser dialogs) all versions prior to 2026.3.812large
  • In Progress® Telerik® UI for AJAX prior to v2026.2.708, a path traversal vulnerability in the file-based persistence storage provider can be exploited when the
    In Progress® Telerik® UI for AJAX prior to v2026.2.708, a path traversal vulnerability in the file-based persistence storage provider can be exploited when the storage key is derived from user-controlled input, enabling attacker-controlled deserialization and remote code execution.
    · progress telerik ui for asp.net ajax
  • In Progress® Telerik® UI for AJAX prior to v2026.2.708, forged upload metadata can influence AsyncUploadTypeName processing and trigger unsafe attacker-controll
    In Progress® Telerik® UI for AJAX prior to v2026.2.708, forged upload metadata can influence AsyncUploadTypeName processing and trigger unsafe attacker-controlled type resolution, enabling remote code execution in affected deployments.
    · progress telerik ui for asp.net ajax
  • In Progress® Telerik® UI for AJAX prior to v2026.2.708, a deserialization vulnerability in the persistence utilities allows unsafe type instantiation from attac
    In Progress® Telerik® UI for AJAX prior to v2026.2.708, a deserialization vulnerability in the persistence utilities allows unsafe type instantiation from attacker-influenced persisted state, which can lead to remote code execution.
    · progress telerik ui for asp.net ajax
  • Unauthenticated Path Traversal File Read in Telerik UI for ASP.NET AJAX RadImageEditor
    Progress Telerik UI for ASP.NET AJAX versions before 2026.3.812 contain a path traversal flaw (CWE-22) in the RadImageEditor control, caused by insufficient validation of client-supplied state. A remote, unauthenticated attacker (per CVSS: AV:N/AC:L/PR:N/UI:N) can submit manipulated state so that the control's image cache returns an attacker-influenced file. Successful abuse can expose the contents of files located outside the intended image directories, producing high confidentiality impact with no integrity or availability impact per the CVSS scoring. Any web application built on Telerik UI for ASP.NET AJAX that exposes RadImageEditor on a version older than 2026.3.812 is affected. There is no known exploitation, no public proof-of-concept, the issue is not in CISA KEV, and EPSS estimates only a 0.4% chance of exploitation within 30 days.
    · Progress Telerik UI for ASP.NET AJAX (RadImageEditor component) prior to 2026.3.812large
  • In Progress® Telerik® UI for AJAX prior to v2026.2.708, when Telerik.Upload.ConfigurationHashKey is absent and machineKey is not explicitly configured, upload m
    In Progress® Telerik® UI for AJAX prior to v2026.2.708, when Telerik.Upload.ConfigurationHashKey is absent and machineKey is not explicitly configured, upload metadata integrity protection may fall back to a predictable default key, enabling attackers to forge protected upload metadata and unlock further exploit chains.
    · progress telerik ui for asp.net ajax
  • In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload upload metadata processing may leak cryptographic validity through measurable timing diff
    In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload upload metadata processing may leak cryptographic validity through measurable timing differences, enabling remote attackers to recover protected metadata values.
    · progress telerik ui for asp.net ajax
  • In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload client-state processing can distinguish decrypt failures from invalid-JSON parse failures
    In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload client-state processing can distinguish decrypt failures from invalid-JSON parse failures, creating an oracle that reveals protected metadata values to remote attackers.
    · progress telerik ui for asp.net ajax

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.