What is CVE-2026-13185?
CVE-2026-13185 is a critical vulnerability in Progress Telerik UI for AJAX prior to v2026.2.708, where RadPersistenceManager or RadDockLayout insecurely deserialize attacker-controlled cookie content. This enables unauthenticated Remote Code Execution (RCE). Users must immediately upgrade to the patched version.
Azərbaycanca: CVE-2026-13185, Telerik UI for AJAX komponentlərindəki zəiflikdir: RadPersistenceManager və RadDockLayout cookie vasitəsilə ötürülən verilənləri təhlükəli şəkildə deserialize edir. Bu, autentifikasiya olunmamış uzaqdan kod icrasına (Remote Code Execution) imkan verir. Tətbiq sahibləri dərhal v2026.2.708 və ya daha yuxarı versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-502; shared vendors: Progress, Telerik
FAQ2
Which Telerik components are affected by CVE-2026-13185?
The RadPersistenceManager and RadDockLayout components insecurely deserialize data passed via cookies.
What is the recommended mitigation for CVE-2026-13185?
Users must immediately upgrade Telerik UI for AJAX to v2026.2.708 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.