CVE-2026-13192: RadEditor PDF Export SSRF Vulnerability in Telerik UI for ASP.NET AJAX
In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of content submitted to the RadEditor PDF export feature may allow an authenticated attacker to trigger server-side requests to arbitrary hosts, resulting in outbound network connections and potential exposure of Windows authentication credentials.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13192?
The severity of CVE-2026-13192 is medium with a score of 6.5.
How do I fix CVE-2026-13192?
To fix CVE-2026-13192, upgrade to Progress Telerik UI for ASP.NET AJAX version 2026.2.708 or later.
What type of vulnerability is CVE-2026-13192?
CVE-2026-13192 is classified as a Server-Side Request Forgery (SSRF) vulnerability.
What can an attacker achieve by exploiting CVE-2026-13192?
An attacker exploiting CVE-2026-13192 may trigger server-side requests to arbitrary hosts, leading to outbound network connections.
Who is affected by CVE-2026-13192?
Users of Progress Telerik UI for ASP.NET AJAX prior to version 2026.2.708 are affected by CVE-2026-13192.