CVE-2026-106155: Stored Cross-site Scripting (XSS) in Telerik Report Server Web Report Viewers
In Progress® Telerik® Report Server prior to version 12.2.26.1007, a stored cross-site scripting vulnerability in the shared reporting engine allows an authenticated report author to embed javascript: or vbscript: URLs in report navigation actions or HTML text box links. When another user views the malicious report and the embedded navigation is triggered, attacker-controlled script can execute in the web report viewer's origin. In a multi-user Report Server deployment, this can enable privilege escalation by performing actions in a higher-privilege user's authenticated session, including an administrator's session.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Progress Telerik Report Serverto a version that resolves this vulnerability.Fixed in 12.2.26.1007
Event History
Frequently Asked Questions
Who is exposed to this issue?
Multi-user Telerik Report Server deployments are exposed when authenticated users can author reports and other users, especially higher-privilege users or administrators, view those reports in the web report viewer.
What does an attacker need to exploit it?
The attacker needs an authenticated report-author account and must create a report containing a javascript: or vbscript: URL in a report navigation action or HTML text box link. A victim must view the malicious report and trigger the embedded navigation.
Are all Report Server versions affected?
The issue affects Progress Telerik Report Server versions prior to 12.2.26.1007.
What is the practical impact if an administrator triggers the malicious link?
Attacker-controlled script can run in the web report viewer's origin under the administrator's authenticated session. This can allow the attacker to perform actions available to that administrator, resulting in privilege escalation.