Impact
A deserialization flaw exists in the PersistenceFramework of Progress Software’s Telerik UI for ASP.NET AJAX before version 2026.2.708, allowing an attacker to influence the persisted state and cause the application to instantiate arbitrary .NET types. This type of weakness is identified as CWE-502 and can enable attackers to execute code on the target system with the permissions of the web application, potentially exposing confidential data, modifying resources, or further compromising the environment.
Affected Systems
The vulnerability affects the Telerik UI for ASP.NET AJAX component of Progress Software. Specifically, versions released prior to 2026.2.708 are impacted. Any deployment or application that incorporates this older component is at risk, regardless of platform, operating system, or hosting environment.
Risk and Exploitability
The CVSS score of 8.1 signals a high severity, indicating that remote exploitation is possible and the impact is large. The EPSS score of <1% indicates a very low but non‑zero probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog, which suggests there are no confirmed exploits in the wild yet; however, deserialization flaws typically attract attackers, making proactive measures advisable.
OpenCVE Enrichment