CVE-2026-14865: XXE Denial of Service via RadLayoutBuilder Client State in Telerik UI for ASP.NET AJAX
In Progress® Telerik® UI for AJAX prior to v2026.2.708, the internal LayoutBuilder control processes client-state XML without disabling DTD processing, allowing unauthenticated denial of service via recursive XML entity expansion.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Progress Telerik UI for AJAX (RadLayoutBuilder / internal LayoutBuilder)to a version that resolves this vulnerability.Fixed in 2026.2.708
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14865?
CVE-2026-14865 has a severity rating of medium with a score of 5.3.
How does CVE-2026-14865 affect Telerik UI for ASP.NET AJAX?
CVE-2026-14865 can lead to a denial of service by allowing unauthenticated users to exploit the internal LayoutBuilder control.
What is the risk associated with CVE-2026-14865?
The risk level for CVE-2026-14865 is rated at 27.
How do I fix CVE-2026-14865?
To mitigate CVE-2026-14865, upgrade Progress Telerik UI for ASP.NET AJAX to version 2026.2.708 or later.
What type of vulnerability is CVE-2026-14865 classified as?
CVE-2026-14865 is classified as an XML External Entity (XXE) vulnerability that can cause denial of service.