Impact
An XML External Entity (XXE) flaw exists in the internal LayoutBuilder control of Progress Software's Telerik UI for ASP.NET AJAX. The control processes client-state XML without disabling DTD processing, allowing an attacker to submit a malicious XML document that expands recursive entity references. The recursive expansion consumes excessive server resources, leading to a denial of service. This is a denial-by-partial-input weakness (CWE-776) and can be triggered without authentication.
Affected Systems
Any installation of Telerik UI for ASP.NET AJAX that uses a version earlier than v2026.2.708 is affected. The Vendor is Progress Software and the product is Telerik UI for ASP.NET AJAX.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. EPSS score is less than 1%, indicating a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that attackers can exploit the flaw by sending a crafted XML payload to the LayoutBuilder client-state endpoint, which requires no special privileges. The resulting denial of service can impact the availability of web applications built with the affected control, making this a noteworthy risk in environments that rely on that component.
OpenCVE Enrichment