CVE-2026-106145: Privilege Escalation in Telerik Report Server Service-Agent Hub
In Progress® Telerik® Report Server prior to version 12.2.26.1007, incorrect privilege assignment in the service-agent SignalR hub allows an authenticated user, including a low-privilege or guest account with a valid bearer token, to register as a trusted service agent. On the next server settings-synchronization event, the rogue agent receives storage settings and encryption private keys. This privilege escalation enables disclosure of protected secrets, including stored data-source credentials and connection strings, and allows agent impersonation and interference with task dispatch.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Progress Telerik Report Serverto a version that resolves this vulnerability.Fixed in 12.2.26.1007
Event History
Frequently Asked Questions
Can a guest or low-privilege account exploit this issue?
Yes. Any authenticated user, including a low-privilege or guest account, can exploit the issue if they have a valid bearer token.
When does the rogue service agent receive sensitive settings?
The rogue agent receives storage settings and encryption private keys during the next server settings-synchronization event after it registers as a trusted service agent.
What information or capabilities can a successful attacker obtain?
A successful attacker can obtain protected secrets, including stored data-source credentials and connection strings. They can also impersonate an agent and interfere with task dispatch.