Junglewise Threat Intelligence

CVE-2026-13192: Progress Telerik UI for ASP.NET AJAX SSRF in RadEditor PDF export

CVE-2026-13192 · Severity: medium · CVSS 6.5 · Published 2026-07-22

Technologies: Progress Software UI for ASP.NET AJAX. Vendors: Progress Software.

Executive brief

Telerik UI for ASP.NET AJAX is a suite of components used to build interactive web applications. A security flaw in its document editor's PDF export feature allows logged-in users to force the web server to make unauthorized network connections. This could lead to the theft of sensitive Windows login credentials or allow attackers to probe the company's internal network.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the RadEditor component of Telerik UI for ASP.NET AJAX due to insufficient validation of content during PDF generation. An authenticated attacker can submit malicious content containing specific URL schemes or UNC paths that the server attempts to resolve when exporting to PDF. This allows the attacker to trigger outbound network requests to arbitrary hosts, which can be used for internal network reconnaissance or to capture Windows NTLM authentication credentials via forced SMB connections. The issue is resolved in version 2026.2.708 (2026 Q2 SP1).

Affected products

  • Progress Software Telerik UI for ASP.NET AJAX 2008.3.1314 through 2026.2.519

Timeline

  • 2026-07-22: advisory: Vendor advisory and CVE published
  • 2026-07-22: patched: Fixed in version 2026.2.708

References