Stored Cross-Site Scripting in Telerik Report Server
CVE-2026-106155
8.9HIGH
Key Information:
- Vendor
Progress Software
- Status
- Vendor
- CVE Published:
- 9 October 2026
What is CVE-2026-106155?
A stored cross-site scripting vulnerability has been identified in Telerik Report Server prior to version 12.2.26.1007, where the shared reporting engine allows authenticated report authors to insert malicious javascript: or vbscript: URLs into report navigation actions or HTML text box links. This vulnerability can be exploited when another user accesses the compromised report, enabling attacker-controlled scripts to execute within the web report viewer’s context. In environments with multiple users, this could permit privilege escalation, allowing attackers to perform actions within the authenticated session of higher-privilege users, including administrators.
Affected Version(s)
Telerik Report Server 0 < 12.2.26.1007