Path Traversal Vulnerability in Telerik UI for AJAX by Progress
CVE-2026-13186

8.1HIGH

What is CVE-2026-13186?

A path traversal vulnerability exists in the file-based persistence storage provider of Telerik UI for AJAX prior to v2026.2.708. This vulnerability can be exploited when the storage key is derived from user-controlled input. Attackers can leverage this flaw to perform unauthorized deserialization, leading to potential remote code execution within the affected system. Implementing proper validation and input sanitization measures can mitigate the risk associated with this security issue.

Affected Version(s)

Telerik UI for ASP.NET AJAX 2013.1.220 < 2026.2.708

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Markus Wulftange with CODE WHITE GmbH
.