Description
In Progress® Telerik® UI for AJAX prior to v2026.2.708, DialogHandler request parameters may be tampered with, potentially altering dialog server-side behavior and enabling chained exploitation.
Published: 2026-07-22
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an attacker to tamper with parameters that are sent to the DialogHandler component of Telerik UI for ASP.NET AJAX. Those parameters influence how the server renders or processes a dialog, so an attacker could cause the server to perform operations that were not intended by the original developer. The manipulation can be leveraged to execute or chain additional attacks, potentially resulting in unauthorized actions performed on the server.

Affected Systems

The flaw affects all installations of Progress Software’s Telerik UI for ASP.NET AJAX that are deployed before version 2026.2.708. Only releases earlier than 2026.2.708 are listed as affected; no other versions appear in the CNA data.

Risk and Exploitability

The CVSS base score of 5.9 indicates a moderate severity. The EPSS score is less than 1 % and the vulnerability is not listed in CISA KEV. Based on the description, the attack vector is inferred to be crafted HTTP requests to the DialogHandler endpoint, requiring network access to the application and the ability to influence the request. No public exploits have been reported, but the potential for chained exploitation raises risk for organizations that expose the UI component externally. Consequently, applying the vendor patch should be treated as a high‑priority security step.

Generated by OpenCVE AI on August 3, 2026 at 23:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to Telerik UI for ASP.NET AJAX v2026.2.708 or later
  • Validate and sanitize DialogHandler request parameters to ensure they conform to expected values
  • Review and restrict application logic that processes dialog operations, ensuring sensitive actions are protected by proper authorization
  • If a patch cannot be applied immediately, restrict external access to the DialogHandler endpoint using authentication or network controls

Generated by OpenCVE AI on August 3, 2026 at 23:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Progress
Progress telerik Ui For Asp.net Ajax
Vendors & Products Progress
Progress telerik Ui For Asp.net Ajax

Wed, 22 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Description In Progress® Telerik® UI for AJAX prior to v2026.2.708, DialogHandler request parameters may be tampered with, potentially altering dialog server-side behavior and enabling chained exploitation.
Title DialogHandler Parameters Tampering Vulnerability in Telerik UI for ASP.NET AJAX
Weaknesses CWE-345
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

Progress Telerik Ui For Asp.net Ajax
cve-icon MITRE

Status: PUBLISHED

Assigner: ProgressSoftware

Published:

Updated: 2026-07-22T19:12:15.521Z

Reserved: 2026-06-24T13:46:41.850Z

Link: CVE-2026-13188

cve-icon Vulnrichment

Updated: 2026-07-22T19:12:11.426Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-22T14:17:14.417

Modified: 2026-08-06T18:03:21.853

Link: CVE-2026-13188

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T23:45:06Z

Weaknesses
  • CWE-345

    Insufficient Verification of Data Authenticity