Description
In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient integrity protection of dialog request parameters used by the RadEditor file browser may allow an attacker who has obtained certain application encryption key material to alter the folders the file browser reads from, writes to, and uploads into, potentially resulting in remote code execution.
Published: 2026-09-02
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote code execution
Action: Patch Now
AI Analysis

Impact

Insufficient integrity protection of dialog request parameters in the RadEditor file browser allows an attacker who has obtained application encryption key material to tamper with the paths the browser uses for reading, writing and uploading files. The manipulation can lead to unintended file operations that may ultimately enable remote code execution within the web application.

Affected Systems

Progress Software’s Telerik UI for ASP.NET AJAX is affected for all releases prior to version 2026.3.812. Any deployment using an earlier build is vulnerable.

Risk and Exploitability

The vulnerability carries a CVSS score of 8.1, classifying it as high severity. Because exploitation requires access to the encrypted key material, the practical likelihood of adversaries exploiting this flaw is limited unless the application’s secret keys are compromised. No known public exploits are listed and the vulnerability is not part of CISA’s KEV catalog, but the high severity and potential for remote code execution warrant proactive remediation.

Generated by OpenCVE AI on September 2, 2026 at 12:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Telerik UI for ASP.NET AJAX to version 2026.3.812 or newer.
  • If an upgrade cannot be performed immediately, enforce strict access controls on the file browser’s directories, disable or tightly restrict upload capabilities, and remove any default or optional subfolders that are not needed.
  • Secure the application’s encryption keys by storing them in an encrypted credential store, rotating key material regularly, and limiting process privileges that can read or write the key files.

Generated by OpenCVE AI on September 2, 2026 at 12:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Progress
Progress telerik Ui For Asp.net Ajax
Vendors & Products Progress
Progress telerik Ui For Asp.net Ajax

Wed, 02 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Description In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient integrity protection of dialog request parameters used by the RadEditor file browser may allow an attacker who has obtained certain application encryption key material to alter the folders the file browser reads from, writes to, and uploads into, potentially resulting in remote code execution.
Title DialogHandler UploadPaths Tampering Vulnerability in Telerik UI for ASP.NET AJAX
Weaknesses CWE-345
CWE-434
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Progress Telerik Ui For Asp.net Ajax
cve-icon MITRE

Status: PUBLISHED

Assigner: ProgressSoftware

Published:

Updated: 2026-09-03T03:56:09.596Z

Reserved: 2026-08-07T08:51:01.356Z

Link: CVE-2026-19219

cve-icon Vulnrichment

Updated: 2026-09-02T12:45:38.510Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-02T11:17:19.270

Modified: 2026-09-08T19:20:25.117

Link: CVE-2026-19219

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T22:00:08Z

Weaknesses
  • CWE-345

    Insufficient Verification of Data Authenticity

  • CWE-434

    Unrestricted Upload of File with Dangerous Type