CVE-2026-19219: DialogHandler UploadPaths Tampering Vulnerability in Telerik UI for ASP.NET AJAX
In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient integrity protection of dialog request parameters used by the RadEditor file browser may allow an attacker who has obtained certain application encryption key material to alter the folders the file browser reads from, writes to, and uploads into, potentially resulting in remote code execution.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Applications using Telerik UI for ASP.NET AJAX versions earlier than v2026.3.812 are affected where the RadEditor file browser is in use. Exploitation also depends on an attacker obtaining certain application encryption key material.
What could an attacker do after obtaining the required key material?
They may tamper with dialog request parameters to change the folders that the RadEditor file browser can read from, write to, and upload files into. This could potentially lead to remote code execution.
What version contains the fix?
Upgrade Telerik UI for ASP.NET AJAX to v2026.3.812 or later.