CVE-2026-13184
Awaiting Analysis Awaiting Analysis - Queue

Telerik UI for AJAX Predictable Upload Metadata Key

Vulnerability report for CVE-2026-13184, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-22

Last updated on: 2026-07-22

Assigner: Progress Software Corporation

Description

In Progress® Telerik® UI for AJAX prior to v2026.2.708, when Telerik.Upload.ConfigurationHashKey is absent and machineKey is not explicitly configured, upload metadata integrity protection may fall back to a predictable default key, enabling attackers to forge protected upload metadata and unlock further exploit chains.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-22
Last Modified
2026-07-22
Generated
2026-07-22
AI Q&A
2026-07-22
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
progress telerik_ui_for_ajax to 2026.2.708 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-321 The product uses a hard-coded, unchangeable cryptographic key.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Progress Telerik UI for AJAX versions before 2026.2.708. If the Telerik.Upload.ConfigurationHashKey setting is missing and the machineKey is not explicitly set, the system may use a predictable default key for upload metadata integrity checks. Attackers can exploit this to forge protected upload metadata, potentially leading to unauthorized actions or further attacks.

Detection Guidance

Check if your Telerik UI for AJAX version is prior to v2026.2.708 by inspecting the assembly version in your application or logs. Review server configurations for the presence of Telerik.Upload.ConfigurationHashKey or explicit machineKey settings in web.config files.

Impact Analysis

Attackers could forge upload metadata to bypass security controls, upload malicious files, or trigger deserialization vulnerabilities. This may lead to remote code execution, data breaches, or system compromise if exploited in applications using vulnerable Telerik UI versions.

Compliance Impact

This vulnerability could lead to unauthorized data access or modification, violating GDPR's integrity and confidentiality principles or HIPAA's security requirements for protected health information. Organizations using affected versions may face compliance violations and potential fines.

Mitigation Strategies

Upgrade Telerik UI for AJAX to v2026.2.708 or later. Ensure Telerik.Upload.ConfigurationHashKey is explicitly configured in the application settings. If not using Telerik, verify machineKey is properly set in web.config to prevent fallback to predictable defaults.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-13184. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart