Impact
The vulnerability exists in the RadImageEditor component of Progress Software’s Telerik UI for ASP.NET AJAX. A client can supply crafted state data that bypasses path validation, allowing the control’s image cache to return arbitrary files. The effect is a confidentiality breach, potentially exposing any files residing on the server beyond the intended image directories. The weakness maps to CWE-22, a path traversal flaw.
Affected Systems
Telerik UI for ASP.NET AJAX implementations running any version earlier than 2026.3.812 are affected. The issue specifically impacts the RadImageEditor control, which can be present in web applications built with this Telerik component suite.
Risk and Exploitability
The CVSS score of 7.5 indicates high impact, but the EPSS score is not available, so current exploitation probability cannot be quantified. The vulnerability is unauthenticated, meaning any external user can craft requests to read files. The lack of a KEV listing suggests no known public exploits yet, but the high severity warrants prompt attention. An attacker, by sending a specially crafted request to the RadImageEditor, can retrieve any file accessible to the application process, potentially including configuration files, secrets, or other sensitive data.
OpenCVE Enrichment