CVE-2026-13187

Progress · Telerik UI for ASP.NET AJAX

Progress Telerik UI for ASP.NET AJAX contains a vulnerability where unauthenticated attackers can use externally controlled input to select arbitrary code or classes for execution.

Executive summary

A high-severity vulnerability in Progress Telerik UI for ASP.NET AJAX allows unauthenticated attackers to influence code execution paths, risking unauthorized application behavior.

Vulnerability

This flaw involves the use of externally controlled input to select classes or code (CWE-470), which can be exploited by an unauthenticated attacker via the network. By tampering with provider types, an attacker may force the application to execute unintended logic.

Business impact

The ability to manipulate code selection can lead to arbitrary code execution or significant logic bypass within the application. With a CVSS score of 8.1, this vulnerability poses a severe threat to the integrity and availability of the affected system. Successful exploitation could allow an attacker to gain control over application functions, potentially leading to unauthorized data modification or total service disruption.

Remediation

Immediate Action: Upgrade the Telerik UI for ASP.NET AJAX framework to version 2026.2.708 or higher.

Proactive Monitoring: Review application logs for unexpected provider type values or suspicious requests directed at the DialogHandler, which may indicate tampering attempts.

Compensating Controls: Utilize a Web Application Firewall (WAF) to inspect incoming requests for anomalous input patterns that deviate from expected application behavior.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for unauthorized code execution, immediate remediation is required. Security teams should verify their current version of Telerik UI and apply the provided vendor patch as soon as possible to secure the application environment.