CVE-2026-13189: SpellChecker DictionaryLanguage Path Traversal Vulnerability in Telerik UI for ASP.NET AJAX
In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of the language parameter in the spell check handler may allow an attacker to influence server-side file path resolution and trigger unintended server-side requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13189?
CVE-2026-13189 has a severity rating of 7.5, indicating it is a high risk vulnerability.
How do I fix CVE-2026-13189?
To fix CVE-2026-13189, upgrade to Progress Telerik UI for AJAX version 2026.2.708 or later.
What type of vulnerability is CVE-2026-13189?
CVE-2026-13189 is a path traversal vulnerability that affects the SpellChecker component in Telerik UI for ASP.NET AJAX.
What can an attacker do with CVE-2026-13189?
An attacker can exploit CVE-2026-13189 to influence server-side file path resolution and execute unintended server-side requests.
Which software is affected by CVE-2026-13189?
CVE-2026-13189 affects Progress Telerik UI for ASP.NET AJAX prior to version 2026.2.708.