What is CVE-2026-13192?
This vulnerability exists in the RadEditor PDF export feature of Progress® Telerik® UI for AJAX, caused by insufficient content validation. An authenticated attacker can exploit this flaw to trigger server-side requests to arbitrary hosts, leading to Server-Side Request Forgery (SSRF) and potential exposure of Windows environment details. Updating to version 2026.2.708 or later is strongly recommended.
Azərbaycanca: Bu zəiflik Progress® Telerik® UI for AJAX platformasının RadEditor PDF ixrac funksiyasında aşkar edilib. Autentifikasiya olunmuş hücumçu, server tərəfindən ixtiyari hostlara şəbəkə sorğuları göndərərək Server-Side Request Forgery (SSRF) hücumu həyata keçirə bilər. 2026.2.708 versiyasından əvvəlki versiyalar istifadə olunursa, təcili yeniləmə aparmaq tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
In which platform and feature was CVE-2026-13192 discovered?
The vulnerability was discovered in the RadEditor PDF export feature of Progress® Telerik® UI for AJAX.
What is the recommended version to mitigate CVE-2026-13192?
Updating to version 2026.2.708 or later is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.