Junglewise Threat Intelligence

CVE-2026-13182: Progress Telerik UI for ASP.NET AJAX padding oracle in RadAsyncUpload

CVE-2026-13182 · Severity: high · CVSS 7.5 · Published 2026-07-22

Technologies: Progress Software UI for ASP.NET AJAX. Vendors: Progress Software.

Executive brief

Progress Telerik UI for ASP.NET AJAX is a suite of components used to build web interfaces. A vulnerability in its file upload component allows remote attackers to bypass security protections on internal metadata. This could lead to the exposure of sensitive configuration data, potentially allowing attackers to gain deeper access to the application or its server.

Technical details

A padding oracle vulnerability exists in the RadAsyncUpload component of Telerik UI for ASP.NET AJAX. The component's client-state processing logic distinguishes between decryption failures and JSON parsing failures, providing a side-channel (oracle) to remote attackers. An unauthenticated attacker can exploit this behavior to reveal protected metadata values without knowledge of the encryption keys. The issue is classified as CWE-209 (Information Exposure Through Error Message) and CAPEC-463 (Padding Oracle Crypto Attack). It has been addressed in version 2026.2.708 by implementing uniform error responses and transitioning to AES-GCM for stronger protection.

Affected products

  • Progress Software Telerik UI for ASP.NET AJAX prior to 2026.2.708

Timeline

  • 2026-07-22: advisory: Initial advisory published by Progress Software
  • 2026-07-22: disclosed

References