SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-13192

MEDIUM · CVSS 6.5 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-07-22 · Last synced 2026-08-21

CyberRota Analysis

AI-Generated

The Telerik UI for AJAX prior to version 2026.2.708 is vulnerable due to inadequate validation in the RadEditor PDF export feature, allowing authenticated attackers to initiate server-side requests to arbitrary hosts. This could lead to unauthorized outbound network connections and the potential exposure of sensitive Windows authentication credentials. Organizations using this software should prioritize remediation to mitigate the risk of credential theft and unauthorized access.

CVE
CVE-2026-13192
Severity
MEDIUM
CVSS
6.5
EPSS
0.24%
Windows

Original NVD Description

In ProgressĀ® TelerikĀ® UI for AJAX prior to v2026.2.708, insufficient validation of content submitted to the RadEditor PDF export feature may allow an authenticated attacker to trigger server-side requests to arbitrary hosts, resulting in outbound network connections and potential exposure of Windows authentication credentials.

Related CVEs

Other vulnerabilities affecting the same vendor(s)