Description
In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of the language parameter in the spell check handler may allow an attacker to influence server-side file path resolution and trigger unintended server-side requests.
Published: 2026-07-22
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

There is an insufficient validation of the language parameter in the spell check handler of Progress Software Telerik UI for ASP.NET AJAX prior to v2026.2.708. The flaw allows an attacker to influence server‑side file path resolution and trigger unintended server‑side requests. This path traversal weakness (CWE‑36) is capable of exposing sensitive files or resources on the host if the server’s file system is not properly guarded.

Affected Systems

Progress Software Telerik UI for ASP.NET AJAX versions earlier than v2026.2.708 are affected.

Risk and Exploitability

The CVSS score of 7.5 classifies this issue as high severity. The EPSS score of < 1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Based on the description it is inferred that an attacker can supply a crafted language parameter in a request to the spell checker endpoint without authentication, although the low EPSS score suggests that actual exploitation is unlikely.

Generated by OpenCVE AI on August 5, 2026 at 01:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor patch or upgrade to Progress Telerik UI for ASP.NET AJAX v2026.2.708 or later.
  • Restrict or remove unauthenticated access to the spell checker endpoint until the patch is applied.
  • Implement server‑side validation or an allow‑list for the language parameter to accept only legitimate values, or add a WAF rule to block suspicious path‑traversal patterns.

Generated by OpenCVE AI on August 5, 2026 at 01:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Progress
Progress telerik Ui For Asp.net Ajax
Vendors & Products Progress
Progress telerik Ui For Asp.net Ajax

Wed, 22 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Description In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of the language parameter in the spell check handler may allow an attacker to influence server-side file path resolution and trigger unintended server-side requests.
Title SpellChecker DictionaryLanguage Path Traversal Vulnerability in Telerik UI for ASP.NET AJAX
Weaknesses CWE-36
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Progress Telerik Ui For Asp.net Ajax
cve-icon MITRE

Status: PUBLISHED

Assigner: ProgressSoftware

Published:

Updated: 2026-07-22T19:11:54.445Z

Reserved: 2026-06-24T13:46:42.510Z

Link: CVE-2026-13189

cve-icon Vulnrichment

Updated: 2026-07-22T19:11:49.762Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-22T14:17:14.537

Modified: 2026-08-06T17:52:29.923

Link: CVE-2026-13189

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T01:15:03Z

Weaknesses
  • CWE-36

    Absolute Path Traversal