Description
In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient integrity protection of dialog request parameters used by the RadEditor file browser may allow an attacker who has obtained certain application encryption key material to alter the folders the file browser reads from, writes to, and uploads into, potentially resulting in remote code execution.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Wed, 02 Sep 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient integrity protection of dialog request parameters used by the RadEditor file browser may allow an attacker who has obtained certain application encryption key material to alter the folders the file browser reads from, writes to, and uploads into, potentially resulting in remote code execution. | |
| Title | DialogHandler UploadPaths Tampering Vulnerability in Telerik UI for ASP.NET AJAX | |
| Weaknesses | CWE-345 CWE-434 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: ProgressSoftware
Published:
Updated: 2026-09-02T12:45:46.169Z
Reserved: 2026-08-07T08:51:01.356Z
Link: CVE-2026-19219
No data.
Status : Received
Published: 2026-09-02T11:17:19.270
Modified: 2026-09-02T11:17:19.270
Link: CVE-2026-19219
No data.
OpenCVE Enrichment
No data.