Path Traversal Vulnerability in Telerik UI for AJAX by Progress
CVE-2026-13186
8.1HIGH
Key Information:
- Vendor
Progress Software
- Vendor
- CVE Published:
- 22 July 2026
What is CVE-2026-13186?
A path traversal vulnerability exists in the file-based persistence storage provider of Telerik UI for AJAX prior to v2026.2.708. This vulnerability can be exploited when the storage key is derived from user-controlled input. Attackers can leverage this flaw to perform unauthorized deserialization, leading to potential remote code execution within the affected system. Implementing proper validation and input sanitization measures can mitigate the risk associated with this security issue.
Affected Version(s)
Telerik UI for ASP.NET AJAX 2013.1.220 < 2026.2.708