In Progress® Telerik® UI for AJAX prior to v2026.2.708, a deserialization vulnerability in the persistence utilities allows unsafe type instantiation from attacker-influenced persisted state, which can lead to remote code execution.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 27 Jul 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Progress
Progress telerik Ui For Asp.net Ajax |
|
| Vendors & Products |
Progress
Progress telerik Ui For Asp.net Ajax |
Wed, 22 Jul 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 22 Jul 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Progress® Telerik® UI for AJAX prior to v2026.2.708, a deserialization vulnerability in the persistence utilities allows unsafe type instantiation from attacker-influenced persisted state, which can lead to remote code execution. | |
| Title | PersistenceFramework Unsafe Type Resolution Vulnerability in Telerik UI for ASP.NET AJAX | |
| Weaknesses | CWE-502 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: ProgressSoftware
Published:
Updated: 2026-07-24T03:56:04.216Z
Reserved: 2026-06-24T13:46:43.300Z
Link: CVE-2026-13190
Updated: 2026-07-22T19:10:52.538Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-02T18:00:05Z
Weaknesses