CVE-2026-2878: Insufficient Entropy Vulnerability in Telerik UI for ASP.NET AJAX
Published Feb 25, 2026
·Updated
In Progress® Telerik® UI for AJAX, versions prior to 2026.1.225, an insufficient entropy vulnerability exists in RadAsyncUpload, where a predictable temporary identifier, based on timestamp and filename, can enable collisions and file content tampering.
Affected Software
2 affected components
Telerik UI for AJAX<2026.1.225
Progress Telerik UI for ASP.NET AJAX<2026.1.225
Event History
Feb 25, 2026
CVE Published
via MITRE·02:45 PM
Data Sourced
via MITRE·02:45 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:20 PM
DescriptionSeverityWeaknessAffected Software
Oct 1, 58139
Event
via FIRST·10:25 AM
Frequently Asked Questions
1
What is the severity of CVE-2026-2878?
CVE-2026-2878 is considered a medium severity vulnerability due to the potential for file content tampering.
2
How do I fix CVE-2026-2878?
To fix CVE-2026-2878, upgrade Telerik UI for AJAX to version 2026.1.225 or later.
3
What software is affected by CVE-2026-2878?
CVE-2026-2878 affects all versions of Telerik UI for AJAX prior to 2026.1.225.
4
What type of vulnerability is CVE-2026-2878?
CVE-2026-2878 is an insufficient entropy vulnerability related to predictable temporary identifiers.
5
What impact does CVE-2026-2878 have on applications?
CVE-2026-2878 can lead to collisions and unauthorized file content tampering in web applications.