Insufficient Integrity Protection in Telerik UI for AJAX File Browser
CVE-2026-19219

8.1HIGH

Key Information:

Vendor
CVE Published:
2 September 2026

What is CVE-2026-19219?

The Telerik UI for AJAX product suffers from a vulnerability where insufficient integrity protection of dialog request parameters used by the RadEditor file browser can be exploited. An attacker with access to specific application encryption key material may manipulate the directories that the file browser interacts with. This capability can allow unauthorized alterations to read, write, and upload folders, creating a gateway for potential remote code execution within the affected application.

Affected Version(s)

Telerik UI for ASP.NET AJAX 2011.2.712 < 2026.3.812

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Marcio Almeida of TantoSec
.