CVE-2026-13181 Details
Description
In Progress® Telerik® UI for AJAX prior to v2026.2.708, forged upload metadata can influence AsyncUploadTypeName processing and trigger unsafe attacker-controlled type resolution, enabling remote code execution in affected deployments.
A remote code execution vulnerability exists in Progress Telerik UI for AJAX versions prior to 2026.2.708. The issue arises in the RadAsyncUpload component, where forged upload metadata can manipulate the handling of AsyncUploadTypeName. This manipulation triggers unsafe type resolution controlled by the attacker, potentially leading to remote code execution on affected systems.
Users are advised to upgrade to Progress Telerik UI for AJAX version 2026.2.708 or later. If an immediate upgrade is not possible, the vulnerability can be mitigated by removing any relevant keys from the web.config file, disabling the RadAsyncUpload handler if not needed, and following instructions for generating strong machine keys.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.telerik.com/products/aspnet-ajax/documentation/knowledge-base/kb-security-rau-asyncuploadtypename-deserialization-CVE-2026-13181 | [email protected] | Vendor AdvisoryMitigation |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-470 | Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| progress telerik ui for asp.net ajax | >= 2010.1309, < 2026.2.708 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 6, 2026 | Initial Analysis | [email protected] |
| Jul 24, 2026 | CVE Modified | CISA-ADP |
| Jul 22, 2026 | CVE Modified | CISA-ADP |
| Jul 22, 2026 | New CVE Received | [email protected] |