Impact
Insufficient integrity protection of dialog request parameters in the RadEditor file browser allows an attacker who has obtained application encryption key material to tamper with the paths the browser uses for reading, writing and uploading files. The manipulation can lead to unintended file operations that may ultimately enable remote code execution within the web application.
Affected Systems
Progress Software’s Telerik UI for ASP.NET AJAX is affected for all releases prior to version 2026.3.812. Any deployment using an earlier build is vulnerable.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.1, classifying it as high severity. Because exploitation requires access to the encrypted key material, the practical likelihood of adversaries exploiting this flaw is limited unless the application’s secret keys are compromised. No known public exploits are listed and the vulnerability is not part of CISA’s KEV catalog, but the high severity and potential for remote code execution warrant proactive remediation.
OpenCVE Enrichment