CVE-2026-13181: RadAsyncUpload AsyncUploadTypeName Type Resolution Vulnerability in Telerik UI for ASP.NET AJAX
In Progress® Telerik® UI for AJAX prior to v2026.2.708, forged upload metadata can influence AsyncUploadTypeName processing and trigger unsafe attacker-controlled type resolution, enabling remote code execution in affected deployments.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Telerik UI for AJAXto a version that resolves this vulnerability.Fixed in v2026.2.708 - Compensating control
Mitigate by preventing or restricting untrusted uploads to RadAsyncUpload (including limiting who can submit AsyncUpload requests), since forged upload metadata can influence AsyncUploadTypeName processing and attacker-controlled type resolution.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13181?
CVE-2026-13181 has a severity score of 8.1, which is classified as high.
How do I fix CVE-2026-13181?
To fix CVE-2026-13181, upgrade to Progress Telerik UI for AJAX version 2026.2.708 or later.
What kind of vulnerability is CVE-2026-13181?
CVE-2026-13181 is a deserialization vulnerability that allows unsafe attacker-controlled type resolution.
What could be the impact of CVE-2026-13181?
CVE-2026-13181 can lead to remote code execution in affected deployments.
Which software is affected by CVE-2026-13181?
CVE-2026-13181 affects Progress Telerik UI for ASP.NET AJAX prior to version 2026.2.708.