CVE-2026-19219 PUBLISHED

DialogHandler UploadPaths Tampering Vulnerability in Telerik UI for ASP.NET AJAX

Assigner: ProgressSoftware
Reserved: 07.08.2026 Published: 02.09.2026 Updated: 02.09.2026

In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient integrity protection of dialog request parameters used by the RadEditor file browser may allow an attacker who has obtained certain application encryption key material to alter the folders the file browser reads from, writes to, and uploads into, potentially resulting in remote code execution.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 8.1

Product Status

Vendor Progress Software
Product Telerik UI for ASP.NET AJAX
Versions Default: unaffected
  • affected from 2011.2.712 to 2026.3.812 (excl.)

Credits

  • Marcio Almeida of TantoSec finder

References

Problem Types

  • CWE-345 Insufficient Verification of Data Authenticity CWE
  • CWE-434 Unrestricted Upload of File with Dangerous Type CWE

Impacts

  • CAPEC-153: Input Data Manipulation