CVE-2026-106155
Received Received - Intake

Stored XSS in Progress Telerik Report Server

Vulnerability report for CVE-2026-106155, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: Progress Software Corporation

Description

In Progress® Telerik® Report Server prior to version 12.2.26.1007, a stored cross-site scripting vulnerability in the shared reporting engine allows an authenticated report author to embed javascript: or vbscript: URLs in report navigation actions or HTML text box links. When another user views the malicious report and the embedded navigation is triggered, attacker-controlled script can execute in the web report viewer's origin. In a multi-user Report Server deployment, this can enable privilege escalation by performing actions in a higher-privilege user's authenticated session, including an administrator's session.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Progress Software Telerik Report Server 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a stored cross-site scripting (XSS) vulnerability in Progress Telerik Report Server versions before 12.2.26.1007. An authenticated report author can insert malicious JavaScript or VBScript URLs in report navigation actions or HTML text boxes. When other users view the report and trigger these actions, the script executes in their session, potentially allowing privilege escalation.

Detection Guidance

To detect this vulnerability, check the version of Progress Telerik Report Server. If it is prior to 12.2.26.1007, the system is vulnerable. Review reports for embedded javascript: or vbscript: URLs in navigation actions or HTML text box links.

Impact Analysis

An attacker with report author access could execute malicious scripts in the context of other users' sessions, including administrators. This could lead to unauthorized actions, data theft, session hijacking, or full system compromise within a multi-user deployment.

Compliance Impact

This vulnerability could lead to unauthorized data access or modification, violating GDPR's integrity and confidentiality principles or HIPAA's safeguards for protected health information. Organizations may face compliance violations, fines, or reputational damage if exploited.

Mitigation Strategies

Immediately update Progress Telerik Report Server to version 12.2.26.1007 or later. Remove or review any existing reports containing suspicious scripts or links.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-106155. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart