CVE-2026-19219
8.1Progress · Telerik UI for ASP.NET AJAX
Progress Telerik UI for ASP.NET AJAX contains an integrity protection flaw in the RadEditor file browser that could allow an attacker with encryption keys to achieve remote code execution.
Executive summary
A critical vulnerability in Progress Telerik UI for ASP.NET AJAX allows unauthenticated remote code execution if an attacker possesses specific application encryption key material.
Vulnerability
The vulnerability arises from insufficient verification of data authenticity within the RadEditor file browser dialog. This allows an unauthenticated attacker to manipulate file path parameters to upload malicious files, provided they have first obtained the necessary application encryption keys.
Business impact
Successful exploitation of this flaw can lead to full remote code execution on the underlying server, granting an attacker complete control over the application environment. Given the CVSS score of 8.1, this represents a high-severity risk that could facilitate data exfiltration, service disruption, and unauthorized access to sensitive corporate infrastructure.
Remediation
Immediate Action: Upgrade to Telerik UI for ASP.NET AJAX version 2026.3.812 or later immediately to apply the necessary integrity checks.
Proactive Monitoring: Monitor server access logs for unusual file upload activity or requests directed at the RadEditor file browser handler that exhibit suspicious path manipulation patterns.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block unauthorized attempts to interact with Telerik dialog handlers or suspicious file upload extensions.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Organizations utilizing Progress Telerik UI for ASP.NET AJAX must treat this vulnerability with high urgency. Administrators should prioritize patching all internet-facing instances of the software to version 2026.3.812. Ensure that application encryption keys are managed securely and rotated regularly, as they serve as a critical component in preventing the successful exploitation of this flaw.
More Progress CVEs
Sources
Originally found and disclosed by Marcio Almeida of TantoSec, per the CVE Program record.