Input Tampering Vulnerability in Telerik UI for AJAX
CVE-2026-13187

8.1HIGH

What is CVE-2026-13187?

The Telerik UI for AJAX framework, specifically prior to version v2026.2.708, is susceptible to input tampering via the DialogHandler provider type. Malicious actors could manipulate this input, potentially affecting the integrity of dialog processing. This vulnerability may facilitate chained exploitation as altered inputs are processed inappropriately, leading to further security risks. It is essential for users to review their implementations and upgrade to the latest versions to mitigate potential threats.

Affected Version(s)

Telerik UI for ASP.NET AJAX 2011.2.712 < 2026.2.708

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Marcio Almeida of TantoSec
.