Executive brief
Progress Telerik UI for ASP.NET AJAX, a popular suite of UI components for web applications, contains a vulnerability in its dialog handling system. An attacker could potentially tamper with request parameters to change how the server processes dialogs, such as those used for file management or text editing. This could lead to further attacks that compromise the application's integrity or security controls.
Technical details
A vulnerability exists in the DialogHandler component of Telerik UI for ASP.NET AJAX due to insufficient verification of data authenticity (CWE-345). The flaw stems from inadequate integrity protection of dialog request parameters, particularly when using RadEditor or RadFileExplorer components. An unauthenticated remote attacker can manipulate these parameters to influence server-side processing, which may serve as a primitive for chained exploitation. The risk is higher in environments where Telerik.Web.UI.DialogParametersEncryptionKey is set in web.config or where machineKey is not explicitly configured. The issue is addressed in version 2026.2.708 (2026 Q2 SP1) by implementing stronger protection via AES-GCM.
Affected products
- Progress Software Telerik UI for ASP.NET AJAX 2011.2.712 through 2026.2.519
Timeline
- 2026-07-22: advisory
- 2026-07-22: disclosed
- 2026-07-22: patched