nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-13181 CVE-2026-13181
HIGH
RadAsyncUpload AsyncUploadTypeName Type Resolution Vulnerability in Telerik UI for ASP.NET AJAX
Record summary
CVE-2026-13181 has a selected CVSS score of 8.1 (high).
Description
In Progress® Telerik® UI for AJAX prior to v2026.2.708, forged upload metadata can influence AsyncUploadTypeName processing and trigger unsafe attacker-controlled type resolution, enabling remote code execution in affected deployments.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 23, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Telerik UI for ASP.NET AJAXBrowse Progress Software / Telerik UI for ASP.NET AJAXDefault status: unaffected | CVE List | 2010.1.309 to < 2026.2.708 | affected |
References
2telerik.comVendor advisory
https://www.telerik.com/products/aspnet-ajax/documentation/knowledge-base/kb-security-rau-asyncuploadtypename-deserialization-CVE-2026-13181