SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-13189

HIGH · CVSS 7.5 EPSS 0.36%

Source: NVD + CISA KEV + EPSS · Published 2026-07-22 · Last synced 2026-08-21

CyberRota Analysis

AI-Generated

The Telerik UI for AJAX prior to version 2026.2.708 is vulnerable due to inadequate validation of the language parameter in the spell check handler, which could enable an attacker to manipulate server-side file path resolution and execute unintended server-side requests. This vulnerability poses a high risk, particularly for organizations using this framework in their web applications. Developers and security teams should prioritize patching this issue to mitigate potential exploitation.

CVE
CVE-2026-13189
Severity
HIGH
CVSS
7.5
EPSS
0.36%

Original NVD Description

In ProgressĀ® TelerikĀ® UI for AJAX prior to v2026.2.708, insufficient validation of the language parameter in the spell check handler may allow an attacker to influence server-side file path resolution and trigger unintended server-side requests.

Related CVEs

Other vulnerabilities affecting the same vendor(s)