CVE-2026-13184: RadAsyncUpload Default HMAC Key Fallback Vulnerability in Telerik UI for ASP.NET AJAX
In Progress® Telerik® UI for AJAX prior to v2026.2.708, when Telerik.Upload.ConfigurationHashKey is absent and machineKey is not explicitly configured, upload metadata integrity protection may fall back to a predictable default key, enabling attackers to forge protected upload metadata and unlock further exploit chains.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Telerik UI for ASP.NET AJAX (RadAsyncUpload)to a version that resolves this vulnerability.Fixed in 2026.2.708 - Configuration
Configure Telerik.Upload.ConfigurationHashKey so it is not absent; do not rely on the predictable default key fallback when machineKey is not explicitly configured.
Telerik Upload Telerik.Upload.ConfigurationHashKey = Set to a non-default secret value (ensure it is present rather than absent)
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13184?
CVE-2026-13184 has a high severity rating of 7.5.
How do I fix CVE-2026-13184?
To fix CVE-2026-13184, ensure that the Telerik.Upload.ConfigurationHashKey is configured and the machineKey settings are explicitly defined.
What impact does CVE-2026-13184 have?
CVE-2026-13184 allows attackers to forge protected upload metadata due to a fallback to a predictable default HMAC key.
Which software is affected by CVE-2026-13184?
CVE-2026-13184 affects Progress Telerik UI for ASP.NET AJAX prior to version 2026.2.708.
When was CVE-2026-13184 published?
CVE-2026-13184 was published on July 22, 2026.