Description
In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of content submitted to the RadEditor PDF export feature may allow an authenticated attacker to trigger server-side requests to arbitrary hosts, resulting in outbound network connections and potential exposure of Windows authentication credentials.
Published: 2026-07-22
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authenticated attacker can exploit insufficient validation in the RadEditor PDF export feature of Progress Telerik UI for ASP.NET AJAX to cause the application server to initiate requests to arbitrary hosts. This Server‑Side Request Forgery (CWE‑918) can result in outbound connections and potentially expose Windows authentication credentials through those requests.

Affected Systems

The vulnerability affects any installation of Progress Software Telerik UI for ASP.NET AJAX that is running a version earlier than 2026.2.708. All earlier releases are at risk when the RadEditor component is enabled and the PDF export function is accessible to authenticated users.

Risk and Exploitability

The CVSS score of 6.5 indicates a medium severity level, and the EPSS score of < 1% indicates a low but nonzero exploitation probability. The issue is not listed in CISA KEV. Because the flaw requires authentication to the RadEditor interface, the attack surface is limited to users who can log into the application, but once authenticated the attacker can target any external host reachable from the server, including internal or publicly reachable services. The risk level remains moderate, but the ability to exfiltrate credentials elevates the potential impact.

Generated by OpenCVE AI on August 3, 2026 at 23:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Telerik UI for ASP.NET AJAX version 2026.2.708 or later, which includes proper validation of the RadEditor PDF export input.
  • If upgrading immediately is not possible, restrict the use of the PDF export functionality to a trusted group of users or disable it entirely in the configuration.
  • Implement network segmentation or firewall rules to limit outbound connections from the application server to only approved destinations, reducing the potential for credential leakage.

Generated by OpenCVE AI on August 3, 2026 at 23:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Progress
Progress telerik Ui For Asp.net Ajax
Vendors & Products Progress
Progress telerik Ui For Asp.net Ajax

Wed, 22 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Description In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of content submitted to the RadEditor PDF export feature may allow an authenticated attacker to trigger server-side requests to arbitrary hosts, resulting in outbound network connections and potential exposure of Windows authentication credentials.
Title RadEditor PDF Export SSRF Vulnerability in Telerik UI for ASP.NET AJAX
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Progress Telerik Ui For Asp.net Ajax
cve-icon MITRE

Status: PUBLISHED

Assigner: ProgressSoftware

Published:

Updated: 2026-07-22T19:10:33.166Z

Reserved: 2026-06-24T13:46:44.046Z

Link: CVE-2026-13192

cve-icon Vulnrichment

Updated: 2026-07-22T19:10:29.322Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-22T14:17:14.777

Modified: 2026-08-06T17:47:06.987

Link: CVE-2026-13192

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T23:45:06Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)