Impact
An authenticated attacker can exploit insufficient validation in the RadEditor PDF export feature of Progress Telerik UI for ASP.NET AJAX to cause the application server to initiate requests to arbitrary hosts. This Server‑Side Request Forgery (CWE‑918) can result in outbound connections and potentially expose Windows authentication credentials through those requests.
Affected Systems
The vulnerability affects any installation of Progress Software Telerik UI for ASP.NET AJAX that is running a version earlier than 2026.2.708. All earlier releases are at risk when the RadEditor component is enabled and the PDF export function is accessible to authenticated users.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity level, and the EPSS score of < 1% indicates a low but nonzero exploitation probability. The issue is not listed in CISA KEV. Because the flaw requires authentication to the RadEditor interface, the attack surface is limited to users who can log into the application, but once authenticated the attacker can target any external host reachable from the server, including internal or publicly reachable services. The risk level remains moderate, but the ability to exfiltrate credentials elevates the potential impact.
OpenCVE Enrichment