Description
In Progress® Telerik® UI for AJAX prior to v2026.2.708, DialogHandler provider type input may be tampered with, potentially altering dialog processing and enabling chained exploitation.
Published: 2026-07-22
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw occurs in the DialogHandler component of Telerik UI for ASP.NET AJAX. A malicious actor can tamper with the provider type input supplied to the dialog request, bypassing normal server‑side validation. This allows the attacker to modify how the dialog is processed, creating a path for chained exploitation in the application. The weakness is an input validation failure, classified as CWE‑470. Attackers could leverage the manipulation to introduce unwanted behavior or, in the worst case, gain higher privileges within the affected application.

Affected Systems

All releases of Progress Software’s Telerik UI for ASP.NET AJAX earlier than version 2026.2.708 are affected. Systems deploying any older build of the UI component that exposes the DialogHandler endpoint are susceptible to the provider type tampering vulnerability.

Risk and Exploitability

The CVSS score of 8.1 indicates a high severity, and the EPSS score of less than 1% suggests a low exploitation probability at the time of this analysis. The vulnerability is not listed in CISA’s KEV catalog, but the risk remains significant for organizations that have exposed the DialogHandler endpoint. The likely attack vector is through any HTTP request to the DialogHandler endpoint, either authenticated or unauthenticated, where an attacker can submit a crafted provider type value. As a result, the flaw could be combined with other weaknesses to enable more serious outcomes. The vulnerability’s practical exploitability depends on how exposed the endpoint is and whether the application implements additional safeguards.

Generated by OpenCVE AI on August 3, 2026 at 23:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Telerik UI for ASP.NET AJAX to version 2026.2.708 or later, which removes the provider type tampering issue.
  • Restrict access to the DialogHandler endpoint by applying network segmentation or firewall rules so that only trusted administrative traffic can reach it.
  • Configure the web application or a WAF to reject unexpected provider type values or to enforce strict validation, providing a temporary defense until the patch is applied.

Generated by OpenCVE AI on August 3, 2026 at 23:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Progress
Progress telerik Ui For Asp.net Ajax
Vendors & Products Progress
Progress telerik Ui For Asp.net Ajax

Wed, 22 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Description In Progress® Telerik® UI for AJAX prior to v2026.2.708, DialogHandler provider type input may be tampered with, potentially altering dialog processing and enabling chained exploitation.
Title DialogHandler Provider Type Tampering Vulnerability in Telerik UI for ASP.NET AJAX
Weaknesses CWE-470
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Progress Telerik Ui For Asp.net Ajax
cve-icon MITRE

Status: PUBLISHED

Assigner: ProgressSoftware

Published:

Updated: 2026-07-24T03:56:03.170Z

Reserved: 2026-06-24T13:46:41.002Z

Link: CVE-2026-13187

cve-icon Vulnrichment

Updated: 2026-07-22T19:12:33.151Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-22T14:17:14.300

Modified: 2026-08-06T18:04:40.850

Link: CVE-2026-13187

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T23:45:06Z

Weaknesses
  • CWE-470

    Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')