What is CVE-2026-13189?
CVE-2026-13189 is a vulnerability in Progress Telerik UI for AJAX, where insufficient validation of the 'language' parameter in the spell check handler prior to v2026.2.708 may allow attackers to influence server-side file path resolution and trigger unintended server-side requests. Affected users should immediately upgrade to the patched version or later.
Azərbaycanca: CVE-2026-13189, Telerik UI for AJAX-in 2026.2.708-dən əvvəlki versiyalarında spell check handler-də `language` parametrinin kifayət qədər yoxlanılmaması səbəbindən server-side file path resolution-a təsir etməyə imkan verən zəiflikdir. Bu, təcavüzkara icazəsiz server sorğuları göndərməyə imkan yarada bilər. Təsirə məruz qalan versiyaları istifadə edən təşkilatlar dərhal göstərilən versiyaya və ya daha yenisinə yeniləmə etməlidir.
Related CVEs
link basis: shared vendor: Progress
FAQ2
Which versions of Telerik UI for AJAX are affected by CVE-2026-13189?
This vulnerability affects versions of Telerik UI for AJAX prior to v2026.2.708.
What should be done to mitigate CVE-2026-13189?
Affected organizations should immediately upgrade Telerik UI for AJAX to version 2026.2.708 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.