CVE-2026-18672 PUBLISHED

RadImageEditor ClientState Unauthenticated Arbitrary File Read Vulnerability in Telerik UI for ASP.NET AJAX

Assigner: ProgressSoftware
Reserved: 03.08.2026 Published: 02.09.2026 Updated: 02.09.2026

In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient validation of client-supplied state in RadImageEditor may allow an attacker to influence which file is returned by the control's image cache, potentially exposing file contents outside the intended image directories.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS Score: 7.5

Product Status

Vendor Progress Software
Product Telerik UI for ASP.NET AJAX
Versions Default: unaffected
  • affected from 2011.2.712 to 2026.3.812 (excl.)

Credits

  • Marcio Almeida of TantoSec finder

References

Problem Types

  • CWE-22 Path Traversal CWE

Impacts

  • CAPEC-126: Path Traversal