CVE-2026-13181
Progress · Telerik UI for ASP.NET AJAX
A vulnerability in Progress Telerik UI for ASP.NET AJAX allows attackers to use externally controlled input to select classes or code, potentially leading to unauthorized execution.
Executive summary
Progress Telerik UI for ASP.NET AJAX is affected by a high-severity vulnerability that could allow attackers to manipulate code execution flows via malicious input.
Vulnerability
This flaw (CWE-470) involves the use of externally controlled input to select classes or code, which can be exploited by unauthenticated remote attackers to influence application behavior.
Business impact
The ability to manipulate application code selection poses a significant risk to data confidentiality and integrity. With a CVSS score of 8.1, this vulnerability could facilitate unauthorized access or remote code execution, leading to potential system-wide impact if left unpatched.
Remediation
Immediate Action: Update Telerik UI for ASP.NET AJAX to version 2026.2.708 or later as directed by the vendor.
Proactive Monitoring: Monitor application logs for unexpected class instantiation errors or anomalous requests targeting the Telerik framework components.
Compensating Controls: Utilize a WAF to filter and validate input parameters, specifically looking for attempts to inject unexpected type names or class references.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the critical nature of Telerik UI components in many enterprise applications, it is imperative to verify current versions immediately. Organizations should apply the provided patch to version 2026.2.708 to protect against potential exploitation of this code selection flaw.