Stored Cross-Site Scripting in Telerik Report Server
CVE-2026-106155

8.9HIGH

Key Information:

Vendor
CVE Published:
9 October 2026

What is CVE-2026-106155?

A stored cross-site scripting vulnerability has been identified in Telerik Report Server prior to version 12.2.26.1007, where the shared reporting engine allows authenticated report authors to insert malicious javascript: or vbscript: URLs into report navigation actions or HTML text box links. This vulnerability can be exploited when another user accesses the compromised report, enabling attacker-controlled scripts to execute within the web report viewer’s context. In environments with multiple users, this could permit privilege escalation, allowing attackers to perform actions within the authenticated session of higher-privilege users, including administrators.

Affected Version(s)

Telerik Report Server 0 < 12.2.26.1007

References

CVSS V3.1

Score:
8.9
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ivan Ivanov
.