CVE-2026-13187: DialogHandler Provider Type Tampering Vulnerability in Telerik UI for ASP.NET AJAX
In Progress® Telerik® UI for AJAX prior to v2026.2.708, DialogHandler provider type input may be tampered with, potentially altering dialog processing and enabling chained exploitation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Telerik UI for ASP.NET AJAXto a version that resolves this vulnerability.Fixed in v2026.2.708
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13187?
The severity of CVE-2026-13187 is high, with a score of 8.1.
How do I fix CVE-2026-13187?
To fix CVE-2026-13187, update Telerik UI for ASP.NET AJAX to version 2026.2.708 or later.
What impact does CVE-2026-13187 have on my application?
CVE-2026-13187 allows tampering with the DialogHandler provider type input, which can alter dialog processing.
Is CVE-2026-13187 exploitable remotely?
Yes, CVE-2026-13187 is exploitable remotely due to its access vector.
What should I do if I'm using a vulnerable version of Telerik UI for ASP.NET AJAX related to CVE-2026-13187?
If you're using a vulnerable version, it's crucial to upgrade to the latest version as soon as possible to mitigate the risk.