Impact
The vulnerability lies in the RadAsyncUpload client-state processing of Telerik UI for ASP.NET AJAX. When a client request fails decryption it produces a different error path than when JSON parsing fails, providing a decrypt‑vs‑parse oracle. This difference can be observed by a remote attacker to reveal protected metadata values embedded in the client state, leading to information disclosure. The weakness is categorized as CWE‑209, a discrepancy in error handling that leaks sensitive data.
Affected Systems
The affected product is Progress Software’s Telerik UI for ASP.NET AJAX. Versions earlier than 2026.2.708 are vulnerable. No product version list beyond the release date is provided, so all pre‑2026.2.708 builds should be considered impacted.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity vulnerability. The EPSS score of 0.00298 indicates a very low but non-zero probability of exploitation. The vulnerability is not currently listed in the CISA KEV catalog. Attackers appear able to trigger the oracle remotely by submitting crafted requests to the RadAsyncUpload component; the exact authentication requirements are not specified, so the potential scope ranges from unauthenticated to authenticated access. Proper mitigation requires patching or disabling the component in environments where it is not needed.
OpenCVE Enrichment