CVE-2026-13190: PersistenceFramework Unsafe Type Resolution Vulnerability in Telerik UI for ASP.NET AJAX
Published Jul 22, 2026
·Updated
In Progress® Telerik® UI for AJAX prior to v2026.2.708, a deserialization vulnerability in the persistence utilities allows unsafe type instantiation from attacker-influenced persisted state, which can lead to remote code execution.
Affected Software
2 affected components
Progress Telerik UI for ASP.NET AJAX<2026.2.708
Progress Telerik UI for ASP.NET AJAX>=2011.2712<2026.2.708
Event History
Jul 22, 2026
CVE Published
via MITRE·01:43 PM
Data Sourced
via MITRE·01:43 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-13190?
CVE-2026-13190 has a severity rating of high with a CVSS score of 8.1.
2
How do I fix CVE-2026-13190?
To fix CVE-2026-13190, upgrade to Progress Telerik UI for AJAX version 2026.2.708 or later.
3
What type of vulnerability is CVE-2026-13190?
CVE-2026-13190 is a deserialization vulnerability that allows unsafe type instantiation.
4
What could be the impact of CVE-2026-13190?
The impact of CVE-2026-13190 could lead to remote code execution from attacker-influenced persisted state.
5
Which software is affected by CVE-2026-13190?
CVE-2026-13190 affects Progress Telerik UI for ASP.NET AJAX prior to version 2026.2.708.