CVE-2026-13185: PersistenceFramework Cookie Deserialization Vulnerability in Telerik UI for ASP.NET AJAX
Published Jul 22, 2026
·Updated
In Progress® Telerik® UI for AJAX prior to v2026.2.708, applications using cookie-based storage in RadPersistenceManager or RadDockLayout deserialize attacker-controlled cookie content, allowing unauthenticated remote code execution.
Affected Software
2 affected components
Progress Telerik UI for AJAX<2026.2.708
Progress Telerik UI for ASP.NET AJAX>=2013.1.220<2026.2.708
Event History
Jul 22, 2026
CVE Published
via MITRE·01:38 PM
Data Sourced
via MITRE·01:38 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-13185?
CVE-2026-13185 has a severity rating of 8.1, categorized as high.
2
What vulnerabilities does CVE-2026-13185 present?
CVE-2026-13185 allows for unauthenticated remote code execution through cookie deserialization in affected Telerik applications.
3
How do I fix CVE-2026-13185?
To fix CVE-2026-13185, upgrade to Progress Telerik UI for AJAX version 2026.2.708 or later.
4
Who is affected by CVE-2026-13185?
Any applications using cookie-based storage in RadPersistenceManager or RadDockLayout prior to version 2026.2.708 are affected by CVE-2026-13185.
5
When was CVE-2026-13185 published?
CVE-2026-13185 was published on July 22, 2026.