Junglewise Threat Intelligence

CVE-2026-18672: Progress Telerik UI for AJAX path traversal in RadImageEditor

CVE-2026-18672 · Severity: high · CVSS 7.5 · Published 2026-09-02

Vendors: Progress.

Executive brief

Progress Telerik UI for AJAX is a suite of web controls used to build dynamic web applications in ASP.NET. The RadImageEditor component contains a path traversal vulnerability that allows an unauthenticated attacker to read arbitrary files from the server by manipulating client-supplied state, potentially exposing sensitive configuration files, source code, or other confidential data outside intended image directories.

Technical details

This is a path traversal vulnerability (CWE-22) in the RadImageEditor control's image cache mechanism. The vulnerability stems from insufficient validation of client-supplied state parameters, allowing an attacker to influence which file is returned by the cache. The attack is network-accessible and requires no authentication or user interaction; the attacker can directly craft malicious requests to access files outside the intended image directories. An attacker can read arbitrary file contents on the affected server. The vulnerability has been patched in version 2026.3.812 (2026 Q3) and later; users on versions prior to 2026.2.708 must upgrade immediately.

Affected products

  • Progress Telerik UI for AJAX prior to 2026.3.812

Timeline

  • 2026-09-02: disclosed: CVE-2026-18672 published

References

Related threats