Executive brief
Progress Telerik UI for ASP.NET AJAX, a popular suite of UI components for web applications, contains a security flaw in how it handles saved application state. If an application is configured to use file-based storage and allows users to influence the storage key (such as through a URL parameter or cookie), an attacker could trick the system into loading malicious files. This can lead to a complete takeover of the web server, allowing unauthorized access to data or disruption of business operations.
Technical details
A path traversal vulnerability (CWE-22) exists in the AppDataStorageProvider of RadPersistenceManager in Telerik UI for ASP.NET AJAX. The flaw occurs when the StorageProviderKey is derived from user-controlled input (e.g., query strings, form fields, or cookies), allowing an attacker to manipulate the file path used for state persistence. By pointing this path to a malicious file—potentially uploaded via other features like RadAsyncUpload—an attacker can trigger insecure deserialization of the file's contents. This chain enables remote code execution (RCE) on the underlying server. The vulnerability is patched in version 2026.2.708 (2026 Q2 SP1).
Affected products
- Progress Software Telerik UI for ASP.NET AJAX >= 2013.1.220, <= 2026.2.519
Timeline
- 2026-07-22: advisory: Initial disclosure by Progress Software
- 2026-07-22: patched: Fix released in version 2026.2.708