CVE-2026-18672: RadImageEditor ClientState Unauthenticated Arbitrary File Read Vulnerability in Telerik UI for ASP.NET AJAX
In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient validation of client-supplied state in RadImageEditor may allow an attacker to influence which file is returned by the control's image cache, potentially exposing file contents outside the intended image directories.
Affected Software
Event History
Frequently Asked Questions
Which deployments are affected?
Progress Telerik UI for ASP.NET AJAX deployments using RadImageEditor are affected if they run a version earlier than v2026.3.812.
Does exploitation require authentication or user interaction?
No. The supplied CVSS vector indicates network-reachable exploitation with low attack complexity, no privileges required, and no user interaction.
What is the impact of successful exploitation?
An attacker may influence the file returned by the RadImageEditor image cache and potentially read contents from outside the intended image directories. The provided severity data indicates high confidentiality impact, with no integrity or availability impact.