No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 09 Oct 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 09 Oct 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Progress Software
Progress Software telerik Report Server |
|
| Vendors & Products |
Progress Software
Progress Software telerik Report Server |
Fri, 09 Oct 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Progress® Telerik® Report Server prior to version 12.2.26.1007, a stored cross-site scripting vulnerability in the shared reporting engine allows an authenticated report author to embed javascript: or vbscript: URLs in report navigation actions or HTML text box links. When another user views the malicious report and the embedded navigation is triggered, attacker-controlled script can execute in the web report viewer's origin. In a multi-user Report Server deployment, this can enable privilege escalation by performing actions in a higher-privilege user's authenticated session, including an administrator's session. | |
| Title | Stored Cross-site Scripting (XSS) in Telerik Report Server Web Report Viewers | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: ProgressSoftware
Published:
Updated: 2026-10-09T18:03:02.317Z
Reserved: 2026-10-06T15:51:11.738Z
Link: CVE-2026-106155
Updated: 2026-10-09T18:02:56.651Z
Status : Deferred
Published: 2026-10-09T08:16:54.377
Modified: 2026-10-09T18:17:02.077
Link: CVE-2026-106155
No data.
OpenCVE Enrichment
Updated: 2026-10-09T09:00:03Z