Description
In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload client-state processing can distinguish decrypt failures from invalid-JSON parse failures, creating an oracle that reveals protected metadata values to remote attackers.
Published: 2026-07-22
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability lies in the RadAsyncUpload client-state processing of Telerik UI for ASP.NET AJAX. When a client request fails decryption it produces a different error path than when JSON parsing fails, providing a decrypt‑vs‑parse oracle. This difference can be observed by a remote attacker to reveal protected metadata values embedded in the client state, leading to information disclosure. The weakness is categorized as CWE‑209, a discrepancy in error handling that leaks sensitive data.

Affected Systems

The affected product is Progress Software’s Telerik UI for ASP.NET AJAX. Versions earlier than 2026.2.708 are vulnerable. No product version list beyond the release date is provided, so all pre‑2026.2.708 builds should be considered impacted.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity vulnerability. The EPSS score of 0.00298 indicates a very low but non-zero probability of exploitation. The vulnerability is not currently listed in the CISA KEV catalog. Attackers appear able to trigger the oracle remotely by submitting crafted requests to the RadAsyncUpload component; the exact authentication requirements are not specified, so the potential scope ranges from unauthenticated to authenticated access. Proper mitigation requires patching or disabling the component in environments where it is not needed.

Generated by OpenCVE AI on August 3, 2026 at 23:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to version 2026.2.708 or later to eliminate the decryption vs parsing error discrepancy.
  • If upgrade is not immediately possible, restrict access to the RadAsyncUpload endpoint or disable the component in environments where it is not needed.
  • Implement monitoring of client‑state error responses to detect attempts to exploit the oracle and block suspicious traffic.

Generated by OpenCVE AI on August 3, 2026 at 23:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Progress
Progress telerik Ui For Asp.net Ajax
Vendors & Products Progress
Progress telerik Ui For Asp.net Ajax

Wed, 22 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Description In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload client-state processing can distinguish decrypt failures from invalid-JSON parse failures, creating an oracle that reveals protected metadata values to remote attackers.
Title RadAsyncUpload Client-State Decrypt-vs-Parse Oracle Vulnerability in Telerik UI for ASP.NET AJAX
Weaknesses CWE-209
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Progress Telerik Ui For Asp.net Ajax
cve-icon MITRE

Status: PUBLISHED

Assigner: ProgressSoftware

Published:

Updated: 2026-07-22T19:14:47.505Z

Reserved: 2026-06-24T13:46:37.358Z

Link: CVE-2026-13182

cve-icon Vulnrichment

Updated: 2026-07-22T19:14:44.286Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-22T14:17:13.683

Modified: 2026-08-06T18:12:29.487

Link: CVE-2026-13182

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T23:45:06Z

Weaknesses
  • CWE-209

    Generation of Error Message Containing Sensitive Information