CVE-2026-13185 Details
Description
In Progress® Telerik® UI for AJAX prior to v2026.2.708, applications using cookie-based storage in RadPersistenceManager or RadDockLayout deserialize attacker-controlled cookie content, allowing unauthenticated remote code execution.
A remote code execution vulnerability exists in Progress Telerik UI for AJAX versions prior to 2026.2.708. The issue arises in applications that use cookie-based storage with RadPersistenceManager or RadDockLayout, allowing deserialization of attacker-controlled cookie data.
Users are advised to upgrade to Progress Telerik UI for AJAX version 2026.2.708 or later. If an immediate upgrade is not possible, do not use CookieStateStorageProvider and ensure that RadDockLayout.LayoutPersistenceRepositoryType is not set to Cookies.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.telerik.com/products/aspnet-ajax/documentation/knowledge-base/kb-security-persistence-cookie-deserialization-CVE-2026-13185 | [email protected] | Vendor AdvisoryMitigation |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-502 | Deserialization of Untrusted Data | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| progress telerik ui for asp.net ajax | >= 2013.1.220, < 2026.2.708 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 6, 2026 | Initial Analysis | [email protected] |
| Jul 24, 2026 | CVE Modified | CISA-ADP |
| Jul 22, 2026 | CVE Modified | CISA-ADP |
| Jul 22, 2026 | New CVE Received | [email protected] |