Remote Code Execution Vulnerability in Telerik UI for AJAX
CVE-2026-13185

8.1HIGH

What is CVE-2026-13185?

Progress Telerik UI for AJAX versions prior to v2026.2.708 suffer from a vulnerability that allows applications utilizing cookie-based storage in RadPersistenceManager or RadDockLayout to inadvertently deserialize attacker-controlled cookie content. This flaw could enable unauthenticated attackers to execute arbitrary code remotely, highlighting the need for organizations to update to the latest version to mitigate potential risks.

Affected Version(s)

Telerik UI for ASP.NET AJAX 2013.1.220 < 2026.2.708

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Markus Wulftange with CODE WHITE GmbH
.