SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-13182

HIGH · CVSS 7.5 EPSS 0.32%

Source: NVD + CISA KEV + EPSS · Published 2026-07-22 · Last synced 2026-08-21

CyberRota Analysis

AI-Generated

The vulnerability affects the Telerik UI for AJAX, specifically in the RadAsyncUpload component, where improper handling of client-state processing can allow remote attackers to differentiate between decryption failures and invalid JSON parse failures. This creates an oracle that can expose sensitive metadata values, potentially leading to unauthorized access to protected information. Organizations using affected versions should prioritize remediation to mitigate the risk of data exposure and maintain the integrity of their applications.

CVE
CVE-2026-13182
Severity
HIGH
CVSS
7.5
EPSS
0.32%
Oracle

Original NVD Description

In ProgressĀ® TelerikĀ® UI for AJAX prior to v2026.2.708, RadAsyncUpload client-state processing can distinguish decrypt failures from invalid-JSON parse failures, creating an oracle that reveals protected metadata values to remote attackers.

Related CVEs

Other vulnerabilities affecting the same vendor(s)