Impact
RadAsyncUpload has an unsafe type resolution flaw in the processing of AsyncUploadTypeName. An attacker who can craft upload metadata can force the framework to load an attacker‑controlled type, which results in arbitrary code execution on the server. The vulnerability is a classic instance of CWE–470 unsafe reflection and can allow remote attackers to run code with the rights of the application process.
Affected Systems
All installations of Progress Software’s Telerik UI for ASP.NET AJAX prior to the v2026.2.708 release are affected. There are no sub‑version exclusions reported; the flaw exists in every build before that version. If the component is deployed on a public or untrusted network surface, the risk is greater because the API is exposed to external requests.
Risk and Exploitability
With a CVSS score of 8.1 the vulnerability is high severity. The EPSS score is less than 1 %, reflecting a low current exploitation probability, and the issue is not listed in the CISA KEV catalog. However, remote code execution can be achieved by sending a specially crafted HTTP upload request, so the likely attack vector is a client‑initiated upload that is not adequately sanitized by the server.
OpenCVE Enrichment