Deserialization Vulnerability in Progress Telerik UI for AJAX
CVE-2026-13190

8.1HIGH

What is CVE-2026-13190?

A vulnerability in the persistence utilities of Progress Telerik UI for AJAX prior to version 2026.2.708 allows for unsafe type instantiation. An attacker can exploit this by manipulating the persisted state, which may lead to remote code execution. Proper security measures and updates are advised to mitigate risks associated with this issue.

Affected Version(s)

Telerik UI for ASP.NET AJAX 2011.2.712 < 2026.2.708

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Progress Telerik Security Team
.