Executive brief
Progress Telerik UI for ASP.NET AJAX, a popular suite of UI components for web applications, contains a security flaw in its file upload component. Under certain configurations, the system uses a predictable security key to protect file upload metadata. An attacker could exploit this to bypass security checks, potentially leading to unauthorized file uploads or further attacks on the web server.
Technical details
A vulnerability exists in the RadAsyncUpload component of Telerik UI for ASP.NET AJAX due to a predictable HMAC key fallback mechanism. When the 'Telerik.Upload.ConfigurationHashKey' is missing and the .NET 'machineKey' is not explicitly configured (left as 'AutoGenerate'), the application falls back to a hard-coded or predictable default key for metadata integrity protection. A remote, unauthenticated attacker can exploit this to forge protected upload metadata, which may serve as a precursor to object injection or unauthorized file uploads. The issue is resolved in version 2026.2.708 (2026 Q2 SP1) by implementing stronger protection via AES-GCM.
Affected products
- Progress Software Telerik UI for ASP.NET AJAX >= 2010.1.309, <= 2026.2.519
Timeline
- 2026-07-22: advisory
- 2026-07-22: disclosed