Impact
The vulnerability allows an attacker to tamper with parameters that are sent to the DialogHandler component of Telerik UI for ASP.NET AJAX. Those parameters influence how the server renders or processes a dialog, so an attacker could cause the server to perform operations that were not intended by the original developer. The manipulation can be leveraged to execute or chain additional attacks, potentially resulting in unauthorized actions performed on the server.
Affected Systems
The flaw affects all installations of Progress Software’s Telerik UI for ASP.NET AJAX that are deployed before version 2026.2.708. Only releases earlier than 2026.2.708 are listed as affected; no other versions appear in the CNA data.
Risk and Exploitability
The CVSS base score of 5.9 indicates a moderate severity. The EPSS score is less than 1 % and the vulnerability is not listed in CISA KEV. Based on the description, the attack vector is inferred to be crafted HTTP requests to the DialogHandler endpoint, requiring network access to the application and the ability to influence the request. No public exploits have been reported, but the potential for chained exploitation raises risk for organizations that expose the UI component externally. Consequently, applying the vendor patch should be treated as a high‑priority security step.
OpenCVE Enrichment