Server-Side Request Forgery in Progress Telerik UI for AJAX
CVE-2026-13192
6.5MEDIUM
Key Information:
- Vendor
Progress Software
- Vendor
- CVE Published:
- 22 July 2026
What is CVE-2026-13192?
The Telerik UI for AJAX contains a vulnerability in its PDF export feature, which lacks adequate validation of user-supplied content. This flaw allows authenticated users to manipulate the system into making server-side requests to uncontrolled hosts. Consequently, this could lead to unauthorized outbound network connections, increasing the risk of exposing sensitive Windows authentication credentials and creating a pathway for further exploitation of the system.
Affected Version(s)
Telerik UI for ASP.NET AJAX 2008.3.1314 < 2026.2.708