Impact
In Progress Telerik Report Server versions earlier than 12.2.26.1007, the SignalR hub used by the service‑agent component assigns incorrect privileges when a user registers an agent. A legitimate user who has only a low‑privilege or guest account, but who possesses a valid bearer token, can therefore register as a trusted service agent. During the next server‑settings‑synchronization event the authenticated user receives the same storage configuration data and encryption private keys that are normally reserved for trusted. This privilege escalation allows the attacker to expose protected secrets such as data‑source credentials, connection strings, and to impersonate or interfere with other task dispatches.
Affected Systems
Affected vendor is Progress Software, product Telerik Report Server. Versions before 12.2.26.1007 are susceptible, as the vulnerability was fixed in that release. No other products or versions are currently documented in the CNA data.
Risk and Exploitability
The CVSS score of 7.1 denotes a high severity vulnerability, but the EPSS score is not available, indicating that the exploitation likelihood is not quantified. Because the flaw requires authenticated access via a bearer token, only users already able to authenticate to the Report Server can exploit it. Nonetheless, the escalation allows disclosure of secrets and manipulation of task dispatch, which could lead to data breaches or service disruption. The vulnerability is not listed in the CISA KEV catalog, so no broader exploitation reports are available as of the given data.
OpenCVE Enrichment