What is CVE-2026-13181?
CVE-2026-13181: In Progress Telerik UI for AJAX before v2026.2.708, forged upload metadata can influence AsyncUploadTypeName processing to trigger unsafe attacker-controlled type resolution, allowing remote code execution. Affected deployments should immediately update to the patched version.
Azərbaycanca: CVE-2026-13181: Progress Telerik UI for AJAX məhsulunda AsyncUploadTypeName emalı zamanı saxta metadata vasitəsilə zərərli tip həlli (type resolution) nəticəsində uzaqdan kod icrası zəifliyi. v2026.2.708 öncəsi versiyalara təsir edir və hücumçuya serverdə kod icra etməyə imkan verir. Dərhal göstərilən versiyaya yenilənmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-502; shared vendor: Progress
FAQ2
Which versions of Progress Telerik UI for AJAX are affected by CVE-2026-13181?
CVE-2026-13181 affects all versions before v2026.2.708.
What is the recommended mitigation for CVE-2026-13181?
Immediate update to v2026.2.708 or later is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.