Junglewise Threat Intelligence

CVE-2026-13187: Progress Telerik UI for ASP.NET AJAX unsafe reflection in DialogHandler

CVE-2026-13187 · Severity: high · CVSS 8.1 · Published 2026-07-22

Technologies: Progress Software UI for ASP.NET AJAX. Vendors: Progress Software.

Executive brief

Progress Telerik UI for ASP.NET AJAX, a popular suite of UI components for web applications, contains a vulnerability in its dialog handling system. An attacker could potentially manipulate how the application processes dialogs, such as those used for file management or text editing. If successfully exploited, this could lead to unauthorized access to sensitive data or allow the attacker to gain further control over the web server.

Technical details

A vulnerability exists in the DialogHandler provider type input of Telerik UI for ASP.NET AJAX due to insufficient validation of externally-controlled input. This flaw, classified as Unsafe Reflection (CWE-470) and Object Injection (CAPEC-586), allows an attacker to tamper with provider type inputs to alter dialog processing. The vulnerability is reachable if RadEditor or RadFileExplorer is used and either a Telerik.Web.UI.DialogParametersEncryptionKey is set or the machineKey is not explicitly configured. While the attack complexity is high, successful exploitation can lead to a full compromise of confidentiality, integrity, and availability. Users are advised to upgrade to version 2026.2.708 or later.

Affected products

  • Progress Software Telerik UI for ASP.NET AJAX >= 2011.2.712, <= 2026.2.519

Timeline

  • 2026-07-22: advisory
  • 2026-07-22: disclosed

References