What is CVE-2026-13182?
CVE-2026-13182 is an oracle vulnerability in Progress Telerik UI for AJAX versions prior to v2026.2.708, where RadAsyncUpload client-state processing can distinguish between decryption and JSON parse failures, allowing remote attackers to reveal protected metadata values. Affected systems should be patched immediately.
Azərbaycanca: CVE-2026-13182, Progress Telerik UI for AJAX-ın v2026.2.708-dən əvvəlki versiyalarında RadAsyncUpload komponentində client-state emalı zamanı şifrə açma xətaları ilə JSON parse xətaları arasında fərq qoya bilməyə imkan verən oracle zəifliyidir. Bu, uzaqdan hücum edənlərə qorunan metadata dəyərlərini aşkar etməyə imkan verir. Hədəfinizdə bu versiya varsa, dərhal yamalanmalıdır.
Related CVEs
link basis: shared vendor: Progress
FAQ2
In which component of Progress Telerik UI for AJAX does the CVE-2026-13182 vulnerability exist?
The vulnerability exists in the RadAsyncUpload component, specifically during client-state processing.
What information can a remote attacker reveal by exploiting the CVE-2026-13182 oracle vulnerability?
Remote attackers can reveal protected metadata values by distinguishing between decryption failures and JSON parse failures.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.