Impact
There is an insufficient validation of the language parameter in the spell check handler of Progress Software Telerik UI for ASP.NET AJAX prior to v2026.2.708. The flaw allows an attacker to influence server‑side file path resolution and trigger unintended server‑side requests. This path traversal weakness (CWE‑36) is capable of exposing sensitive files or resources on the host if the server’s file system is not properly guarded.
Affected Systems
Progress Software Telerik UI for ASP.NET AJAX versions earlier than v2026.2.708 are affected.
Risk and Exploitability
The CVSS score of 7.5 classifies this issue as high severity. The EPSS score of < 1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Based on the description it is inferred that an attacker can supply a crafted language parameter in a request to the spell checker endpoint without authentication, although the low EPSS score suggests that actual exploitation is unlikely.
OpenCVE Enrichment