CVE-2026-19219
Received Received - Intake

Insufficient Integrity Protection in Telerik UI for AJAX Leading to RCE

Vulnerability report for CVE-2026-19219, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-02

Last updated on: 2026-09-02

Assigner: Progress Software Corporation

Description

In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient integrity protection of dialog request parameters used by the RadEditor file browser may allow an attacker who has obtained certain application encryption key material to alter the folders the file browser reads from, writes to, and uploads into, potentially resulting in remote code execution.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-02
Last Modified
2026-09-02
Generated
2026-09-02
AI Q&A
2026-09-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
progress telerik_ui_for_ajax to 2026.3.812 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
CWE-345 The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Progress Telerik UI for AJAX before version 2026.3.812. It involves insufficient integrity protection of dialog request parameters in the RadEditor file browser. An attacker with access to application encryption keys could manipulate these parameters to change which folders the file browser accesses, potentially leading to remote code execution.

Impact Analysis

If exploited, this vulnerability could allow an attacker to read, write, or upload files to unauthorized folders on your system. This may result in remote code execution, data theft, or system compromise, depending on the attacker's goals and your application's permissions.

Compliance Impact

This vulnerability could lead to unauthorized data access or modification, violating GDPR's data integrity and confidentiality requirements or HIPAA's safeguards for protected health information. Non-compliance risks include legal penalties, reputational damage, and loss of trust.

Mitigation Strategies

Update Progress Telerik UI for AJAX to version 2026.3.812 or later to address the vulnerability.

Review and restrict access to application encryption key material to prevent unauthorized parameter tampering.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19219. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart