Impact
This vulnerability allows an attacker to trigger remote code execution in applications that use Progress Telerik UI for ASP.NET AJAX before version 2026.2.708. Attacker‑controlled data placed in a cookie is deserialized by the RadPersistenceManager or RadDockLayout components. Because the deserialized objects are not validated, an attacker can execute arbitrary code on the server. The associated weakness is CWE‑502: Deserialization of Untrusted Data.
Affected Systems
Progress Software’s Telerik UI for ASP.NET AJAX is affected for all releases preceding v2026.2.708. Any deployment that relies on cookie‑based storage in the RadPersistenceManager or RadDockLayout is vulnerable; versions v2026.2.708 and later contain the fix.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity, and the EPSS score is <1%. The vulnerability is not listed in KEV, suggesting no known widespread exploitation. The likely attack vector is via a crafted HTTP cookie sent to the application, enabling an unauthenticated attacker to reach the vulnerable deserialization endpoint. An exploit would result in full compromise of the application without authentication.
OpenCVE Enrichment