Description
In Progress® Telerik® Report Server prior to version 12.2.26.1007, incorrect privilege assignment in the service-agent SignalR hub allows an authenticated user, including a low-privilege or guest account with a valid bearer token, to register as a trusted service agent. On the next server settings-synchronization event, the rogue agent receives storage settings and encryption private keys. This privilege escalation enables disclosure of protected secrets, including stored data-source credentials and connection strings, and allows agent impersonation and interference with task dispatch.
Published: 2026-10-09
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Privilege Escalation and Secrets Disclosure
Action: Apply Patch
AI Analysis

Impact

In Progress Telerik Report Server versions earlier than 12.2.26.1007, the SignalR hub used by the service‑agent component assigns incorrect privileges when a user registers an agent. A legitimate user who has only a low‑privilege or guest account, but who possesses a valid bearer token, can therefore register as a trusted service agent. During the next server‑settings‑synchronization event the authenticated user receives the same storage configuration data and encryption private keys that are normally reserved for trusted. This privilege escalation allows the attacker to expose protected secrets such as data‑source credentials, connection strings, and to impersonate or interfere with other task dispatches.

Affected Systems

Affected vendor is Progress Software, product Telerik Report Server. Versions before 12.2.26.1007 are susceptible, as the vulnerability was fixed in that release. No other products or versions are currently documented in the CNA data.

Risk and Exploitability

The CVSS score of 7.1 denotes a high severity vulnerability, but the EPSS score is not available, indicating that the exploitation likelihood is not quantified. Because the flaw requires authenticated access via a bearer token, only users already able to authenticate to the Report Server can exploit it. Nonetheless, the escalation allows disclosure of secrets and manipulation of task dispatch, which could lead to data breaches or service disruption. The vulnerability is not listed in the CISA KEV catalog, so no broader exploitation reports are available as of the given data.

Generated by OpenCVE AI on October 9, 2026 at 08:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Progress Telerik Report Server to version 12.2.26.1007 or later to apply the official fix.
  • If an upgrade is not immediately possible, restrict the service‑agent registration feature to only users with higher privilege levels by adjusting role permissions or disabling the service‑agent hub for low‑privilege accounts.
  • After remediation, rotate or regenerate the storage encryption keys and any stored passwords to invalidate any secrets that may have been exposed during the window of vulnerability.

Generated by OpenCVE AI on October 9, 2026 at 08:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Progress
Progress telerik Report Server
Vendors & Products Progress
Progress telerik Report Server

Fri, 09 Oct 2026 07:45:00 +0000

Type Values Removed Values Added
Description In Progress® Telerik® Report Server prior to version 12.2.26.1007, incorrect privilege assignment in the service-agent SignalR hub allows an authenticated user, including a low-privilege or guest account with a valid bearer token, to register as a trusted service agent. On the next server settings-synchronization event, the rogue agent receives storage settings and encryption private keys. This privilege escalation enables disclosure of protected secrets, including stored data-source credentials and connection strings, and allows agent impersonation and interference with task dispatch.
Title Privilege Escalation in Telerik Report Server Service-Agent Hub
Weaknesses CWE-266
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Progress Telerik Report Server
cve-icon MITRE

Status: PUBLISHED

Assigner: ProgressSoftware

Published:

Updated: 2026-10-09T07:03:34.351Z

Reserved: 2026-10-06T15:51:10.392Z

Link: CVE-2026-106145

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T08:16:54.250

Modified: 2026-10-09T08:16:54.250

Link: CVE-2026-106145

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T09:30:03Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment