What is CVE-2026-13184?
CVE-2026-13184 affects Progress Telerik UI for AJAX before v2026.2.708. When machineKey is not explicitly configured, upload metadata integrity protection falls back to a predictable default key, allowing attackers to forge protected upload metadata.
Azərbaycanca: Progress Telerik UI for AJAX-da CVE-2026-13184 zəifliyi aşkarlanıb. v2026.2.708 öncəsi versiyalarda machineKey açıq şəkildə konfiqurasiya edilmədikdə, yükləmə metadata bütövlüyü qorunması proqnozlaşdırıla bilən defolt açara düşür. Bu, hücumçulara saxta upload metadata yaratmağa imkan verir.
Related CVEs
link basis: same weakness class CWE-798
FAQ2
Which product is affected by CVE-2026-13184?
This vulnerability affects Progress Telerik UI for AJAX versions prior to v2026.2.708.
How is CVE-2026-13184 exploited?
When machineKey is not explicitly configured, upload metadata integrity protection falls back to a predictable default key, allowing attackers to forge protected upload metadata.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.