What is CVE-2026-13186?
In Progress Telerik UI for AJAX versions prior to v2026.2.708, a path traversal vulnerability exists in the file-based persistence storage provider. When the storage key is derived from user-controlled input, this flaw enables attacker-controlled deserialization, potentially leading to remote code execution (RCE). Immediate update to the patched version is strongly recommended for all affected systems.
Azərbaycanca: Progress Telerik UI for AJAX-ın v2026.2.708-dən əvvəlki versiyalarında fayl əsaslı yaddaş saxlayıcısında (file-based persistence storage provider) path traversal zəifliyi aşkarlanıb. Saxlama açarı (storage key) istifadəçi tərəfindən idarə olunan məlumatlardan törədildikdə, bu boşluq uzaqdan kod icrasına (RCE) səbəb ola biləcək zərərli deserializasiyaya şərait yaradır. Təsirə məruz qalan sistemlərdə istismarın qarşısını almaq üçün dərhal göstərilən versiyaya və ya daha yenisinə yeniləmə tövsiyə olunur.
Related CVEs
link basis: shared vendors: Progress, Telerik
FAQ2
Which versions of Progress Telerik UI for AJAX are affected by CVE-2026-13186?
All versions prior to v2026.2.708 are affected by this vulnerability.
What is the most critical potential outcome if CVE-2026-13186 is exploited?
Remote code execution (RCE) can occur through attacker-controlled deserialization.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.