CVE-2026-6023: Deserialization of Untrusted Data Vulnerability in Telerik UI for ASP.NET AJAX
In Progress® Telerik® UI for AJAX versions 2024.4.1114 through 2026.1.421, the RadFilter control is vulnerable to insecure deserialization when restoring filter state if the state is exposed to the client. If an attacker tampers with this state, a server-side remote code execution is possible.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Telerik UI for ASP.NET AJAX (RadFilter)to a version that resolves this vulnerability.Fixed in 2026.1.421
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6023?
CVE-2026-6023 is considered a high-severity vulnerability due to the potential for remote code execution.
How do I fix CVE-2026-6023?
To fix CVE-2026-6023, update the Telerik UI for ASP.NET AJAX to version 2026.1.422 or later.
What software is affected by CVE-2026-6023?
CVE-2026-6023 affects Progress Telerik UI for ASP.NET AJAX versions from 2024.4.1114 to 2026.1.421.
What are the risks associated with CVE-2026-6023?
The risks associated with CVE-2026-6023 include potential unauthorized access and manipulation of application data due to insecure deserialization.
Is CVE-2026-6023 specific to any particular component?
Yes, CVE-2026-6023 specifically affects the RadFilter control within Telerik UI for AJAX.