CVE-2026-13186: AppDataStorageProvider Path Traversal Deserialization Vulnerability in Telerik UI for ASP.NET AJAX
In Progress® Telerik® UI for AJAX prior to v2026.2.708, a path traversal vulnerability in the file-based persistence storage provider can be exploited when the storage key is derived from user-controlled input, enabling attacker-controlled deserialization and remote code execution.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Telerik UI for ASP.NET AJAXto a version that resolves this vulnerability.Fixed in v2026.2.708
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13186?
The severity of CVE-2026-13186 is rated high with a CVSS score of 8.1.
How do I fix CVE-2026-13186?
To fix CVE-2026-13186, upgrade to Telerik UI for ASP.NET AJAX version 2026.2.708 or later.
What type of vulnerability is CVE-2026-13186?
CVE-2026-13186 is a path traversal deserialization vulnerability.
What are the potential impacts of CVE-2026-13186?
CVE-2026-13186 can lead to attacker-controlled deserialization and potentially remote code execution.
Which software is affected by CVE-2026-13186?
CVE-2026-13186 affects Telerik UI for ASP.NET AJAX prior to version 2026.2.708.