New Telerik UI for ASP.NET AJAX vulnerability exposes path traversal

According to Progress Telerik, UI for ASP.NET AJAX components have template injection vulnerabilities that lead to path traversal. The affected components include:

RadImageEditor - affected versions: v2011.2.712 to v2026.2.708
RadEditor (DialogHandler) - affected versions: v2011.2.712 to v2026.2.708

There is no CVE for this vulnerability yet, but Progress Telerik advises that users upgrade to 2026 Q3 (v2026.3.812) as their earliest opportunity. Customers can request further assistance at https://prgress.co/DevToolsSupport

There are no known exploits in the wild for this vulnerability, nor are there IoCs. Because the bulk of the processing is client-side, the attack appears silent to the server administrator.

1 Like