Server-Side Request Forgery in Progress Telerik UI for AJAX
CVE-2026-13192

6.5MEDIUM

What is CVE-2026-13192?

The Telerik UI for AJAX contains a vulnerability in its PDF export feature, which lacks adequate validation of user-supplied content. This flaw allows authenticated users to manipulate the system into making server-side requests to uncontrolled hosts. Consequently, this could lead to unauthorized outbound network connections, increasing the risk of exposing sensitive Windows authentication credentials and creating a pathway for further exploitation of the system.

Affected Version(s)

Telerik UI for ASP.NET AJAX 2008.3.1314 < 2026.2.708

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Marcio Almeida of TantoSec
.