SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-13183

HIGH · CVSS 7.5 EPSS 0.32%

Source: NVD + CISA KEV + EPSS · Published 2026-07-22 · Last synced 2026-08-21

CyberRota Analysis

AI-Generated

The Telerik UI for AJAX, prior to version 2026.2.708, is vulnerable due to timing discrepancies in the RadAsyncUpload component, which can lead to the exposure of cryptographic metadata to remote attackers. This vulnerability poses a significant risk as it allows attackers to potentially recover sensitive information, compromising the integrity of the application. Organizations using this component should prioritize remediation to mitigate the risk of data leaks and enhance their security posture.

CVE
CVE-2026-13183
Severity
HIGH
CVSS
7.5
EPSS
0.32%

Original NVD Description

In ProgressĀ® TelerikĀ® UI for AJAX prior to v2026.2.708, RadAsyncUpload upload metadata processing may leak cryptographic validity through measurable timing differences, enabling remote attackers to recover protected metadata values.

Related CVEs

Other vulnerabilities affecting the same vendor(s)