CVE-2026-18672
Received Received - Intake

Insufficient State Validation in Telerik UI for AJAX Leads to File Exposure

Vulnerability report for CVE-2026-18672, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-02

Last updated on: 2026-09-02

Assigner: Progress Software Corporation

Description

In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient validation of client-supplied state in RadImageEditor may allow an attacker to influence which file is returned by the control's image cache, potentially exposing file contents outside the intended image directories.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-02
Last Modified
2026-09-02
Generated
2026-09-02
AI Q&A
2026-09-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
progress telerik_ui_for_ajax to 2026.3.812 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability exists in Progress Telerik UI for AJAX before version 2026.3.812. It involves insufficient validation of client-supplied state in the RadImageEditor component, allowing an attacker to manipulate the image cache to access files outside the intended directories.

Detection Guidance
  • Check Telerik UI for AJAX version installed. If it is prior to v2026.3.812, the system is vulnerable.
  • Review server logs for unusual file access patterns or requests to RadImageEditor endpoints.
  • Use network monitoring tools to detect unexpected outbound or inbound traffic related to image caching.
Impact Analysis

An attacker could exploit this to read sensitive files on the server, potentially exposing confidential data such as configuration files, user credentials, or other restricted information stored outside the intended image directories.

Compliance Impact

This vulnerability could lead to unauthorized data exposure, violating GDPR's data protection principles or HIPAA's requirements for safeguarding protected health information, potentially resulting in legal penalties and reputational damage.

Mitigation Strategies
  • Upgrade Telerik UI for AJAX to version v2026.3.812 or later immediately.
  • Apply input validation to restrict file paths in RadImageEditor requests.
  • Restrict access to RadImageEditor endpoints via firewall rules or network segmentation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18672. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart