Executive brief
A vulnerability exists in Telerik UI for ASP.NET AJAX, a popular suite of UI components used for building web applications. If an application is configured to store user interface settings (like layout or persistence) in browser cookies, an attacker can send a specially crafted cookie to take full control of the web server. This could lead to the theft of sensitive customer data, complete service disruption, or a total compromise of the hosting environment.
Technical details
A deserialization of untrusted data vulnerability (CWE-502) exists in the RadPersistenceManager and RadDockLayout components of Telerik UI for ASP.NET AJAX. When these components are explicitly configured to use cookie-based storage (CookieStateStorageProvider or LayoutPersistenceRepositoryType set to Cookies), they fail to properly validate or sanitize the contents of the incoming cookie before deserialization. An unauthenticated remote attacker can exploit this by providing a malicious serialized object within a cookie, leading to arbitrary code execution on the server. The vulnerability is addressed in version 2026.2.708 (2026 Q2 SP1).
Affected products
- Progress Software Telerik UI for ASP.NET AJAX >= 2013.1.220, <= 2026.2.519
Timeline
- 2026-07-22: disclosed
- 2026-07-22: advisory
- 2026-07-22: patched