CVE-2026-13182: RadAsyncUpload Client-State Decrypt-vs-Parse Oracle Vulnerability in Telerik UI for ASP.NET AJAX
Published Jul 22, 2026
·Updated
In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload client-state processing can distinguish decrypt failures from invalid-JSON parse failures, creating an oracle that reveals protected metadata values to remote attackers.
Affected Software
2 affected components
Progress Telerik UI for ASP.NET AJAX<2026.2.708
Progress Telerik UI for ASP.NET AJAX>=2010.1309<2026.2.708
Event History
Jul 22, 2026
CVE Published
via MITRE·01:34 PM
Data Sourced
via MITRE·01:34 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-13182?
CVE-2026-13182 has a severity rating of 7.5, categorized as high.
2
What type of vulnerability is CVE-2026-13182?
CVE-2026-13182 is an oracle vulnerability that affects the RadAsyncUpload feature in Telerik UI for ASP.NET AJAX.
3
How do I fix CVE-2026-13182?
To resolve CVE-2026-13182, upgrade to Progress Telerik UI for AJAX version v2026.2.708 or later.
4
What can attackers gain from exploiting CVE-2026-13182?
Exploiting CVE-2026-13182 may allow attackers to reveal protected metadata values due to discernible differences in client-state processing.
5
Which software is affected by CVE-2026-13182?
CVE-2026-13182 affects Progress Telerik UI for ASP.NET AJAX prior to version 2026.2.708.