Executive brief
Progress Telerik UI for ASP.NET AJAX, a popular suite of UI components for web applications, contains a security flaw in its persistence framework. If an attacker can modify the data stored by the application's state management system, they could potentially execute malicious code on the server. This could lead to a complete takeover of the affected web server and unauthorized access to sensitive data.
Technical details
A deserialization vulnerability (CWE-502) exists in the RadPersistenceManager component of Telerik UI for ASP.NET AJAX. The flaw is rooted in the PersistenceFramework's handling of persisted state, where unsafe type instantiation can occur if an attacker can influence the storage source (e.g., via file-based or cookie-based storage). Exploitation requires the application to be configured such that the StorageProviderKey is derived from user-controlled input or the storage medium itself is writable by the attacker. Successful exploitation allows for Object Injection (CAPEC-586) and Remote Code Execution (RCE). The issue is resolved in version 2026.2.708 (2026 Q2 SP1).
Affected products
- Progress Software Telerik UI for ASP.NET AJAX >= 2011.2.712, < 2026.2.708
Timeline
- 2026-07-22: advisory: Vendor advisory and NVD entry published
- 2026-07-22: patched: Fix released in version 2026.2.708