CVE-2026-106145 PUBLISHED

Privilege Escalation in Telerik Report Server Service-Agent Hub

Assigner: ProgressSoftware
Reserved: 06.10.2026 Published: 09.10.2026 Updated: 09.10.2026

In Progress® Telerik® Report Server prior to version 12.2.26.1007, incorrect privilege assignment in the service-agent SignalR hub allows an authenticated user, including a low-privilege or guest account with a valid bearer token, to register as a trusted service agent. On the next server settings-synchronization event, the rogue agent receives storage settings and encryption private keys. This privilege escalation enables disclosure of protected secrets, including stored data-source credentials and connection strings, and allows agent impersonation and interference with task dispatch.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
CVSS Score: 7.1

Product Status

Vendor Progress Software
Product Telerik Report Server
Versions Default: unaffected
  • affected from 0 to 12.2.26.1007 (excl.)

Credits

  • Ivan Ivanov finder

References

Problem Types

  • CWE-266 Incorrect Privilege Assignment CWE

Impacts

  • Privilege Escalation