CyberRota Analysis
AI-GeneratedTelerik UI for AJAX versions prior to 2026.3.812 are vulnerable due to inadequate validation of client-supplied state in the RadImageEditor component, which could allow attackers to manipulate the image cache and access unauthorized file contents. This vulnerability poses a significant risk of data exposure, making it critical for organizations using this software to prioritize immediate updates to mitigate potential exploitation. Security teams and developers utilizing Telerik UI should take action to ensure their systems are patched.
Original NVD Description
In ProgressĀ® TelerikĀ® UI for AJAX prior to v2026.3.812, insufficient validation of client-supplied state in RadImageEditor may allow an attacker to influence which file is returned by the control's image cache, potentially exposing file contents outside the intended image directories.