Cross-Site Scripting Vulnerability in Kendo UI for Vue by Progress
CVE-2026-106139

5.4MEDIUM

Key Information:

Vendor
CVE Published:
10 October 2026

What is CVE-2026-106139?

Kendo UI for Vue contains a vulnerability where chart tooltips render formatted values as unencoded HTML. This flaw allows an attacker with limited privileges to inject malicious JavaScript into the application. By manipulating the input bound to the chart, an unauthorized user could execute arbitrary scripts in the context of a user's browser, potentially compromising sensitive information. It is crucial for users of the affected versions to apply necessary updates and strengthen their security measures.

Affected Version(s)

Kendo UI for Vue 2.5.0 < 10.1.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Abhishek Nandkumar Bhaskar (Abhi-Hackz)
.