What is CVE-2026-14865?
This vulnerability exists in the LayoutBuilder control of Progress Telerik UI for AJAX. An unauthenticated attacker can cause a denial of service (DoS) via recursive XML entity expansion (XXE) due to the processing of client-state XML without disabling DTD processing. Upgrading to version v2026.2.708 or later is recommended.
Azərbaycanca: Bu zəiflik Progress Telerik UI for AJAX məhsulunun LayoutBuilder nəzarətçisində aşkarlanıb. Autentifikasiya olunmamış hücumçu recursive XML entity expansion (XXE) vasitəsilə xidmətə qarşı denial of service (DoS) hücumu həyata keçirə bilər. Məhsulu v2026.2.708 və ya daha yeni versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-611
FAQ2
Which control in Progress Telerik UI for AJAX is affected by CVE-2026-14865?
The LayoutBuilder control is affected.
To which version should one upgrade to mitigate CVE-2026-14865?
Upgrading to version v2026.2.708 or later is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.