Junglewise Threat Intelligence

CVE-2026-13181: Progress Telerik UI for ASP.NET AJAX remote code execution in RadAsyncUpload

CVE-2026-13181 · Severity: high · CVSS 8.1 · Published 2026-07-22

Technologies: Progress Software UI for ASP.NET AJAX. Vendors: Progress Software.

Executive brief

Progress Telerik UI for ASP.NET AJAX, a popular suite of components for building web applications, contains a vulnerability in its file upload component. An attacker can exploit this by sending specially crafted file upload metadata to the server, potentially allowing them to execute unauthorized code. This could lead to a full system compromise, data theft, or service disruption.

Technical details

A vulnerability exists in the RadAsyncUpload component of Telerik UI for ASP.NET AJAX (CWE-470/CAPEC-586) due to the use of externally-controlled input to select classes or code. Specifically, forged upload metadata can influence the 'AsyncUploadTypeName' processing, triggering unsafe attacker-controlled type resolution. This deserialization-like flaw allows an unauthenticated remote attacker to achieve remote code execution (RCE). The attack requires the RadAsyncUpload handler to be enabled. A fix is available in version 2026.2.708, which implements stronger protection via AES-GCM for configuration keys.

Affected products

  • Progress Software Telerik UI for ASP.NET AJAX >= 2010.1.309, <= 2026.2.519

Timeline

  • 2026-07-22: advisory
  • 2026-07-22: patched

References