Telerik: from a padding oracle to unauthenticated RCE

Researchers at Tanto Security discovered several vulnerabilities in Telerik UI for ASP.NET AJAX and chained them to achieve unauthenticated RCE under specific configurations.
The attack is based on CVE-2026-13182, an AES-CBC padding oracle in RadAsyncUpload: the server handles invalid padding differently from valid padding followed by invalid JSON. By distinguishing these responses, an attacker can forge an encrypted configuration with chosen values without knowing the AES key — for example, to allow DLL uploads.
After uploading a DLL, the same oracle can be used to forge the encrypted metaData and set AsyncUploadTypeName to System.Configuration.Install.AssemblyInstaller. This is where CVE-2026-13181 comes into play: Telerik passes the attacker-controlled type to Type.GetType() without restricting it to an allowlist of expected types. Through AssemblyInstaller.Path, the attacker points to the uploaded DLL, causing Assembly.LoadFrom() to load it; a mixed-mode C++/CLI DLL then executes native code through DllMain.
The full chain is: padding oracle → configuration forgery → DLL upload → metaData forgery → AssemblyInstaller → DLL loading → RCE.
If customErrors=On hides the difference between the error responses, CVE-2026-13183 provides a timing variant of the same oracle by exploiting the difference in execution time between the two processing paths.
Another vulnerability, CVE-2026-13184, involves a predictable fallback HMAC key for TempTargetFolder and, under certain configurations, allows an attacker to choose the upload directory. It is not required for the RCE chain demonstrated in the research.
Full exploitation requires a reachable page containing RadAsyncUpload, a server-side FileUploaded handler that reads UploadResult, and an explicitly configured Telerik.AsyncUpload.ConfigurationEncryptionKey. In a lab test, the exploit made roughly 127,000 oracle requests at about 30 requests per second and obtained a shell in just over an hour.
Progress fixed the vulnerabilities in Telerik UI for ASP.NET AJAX 2026.2.708 by replacing AES-CBC with AES-GCM, thereby eliminating both padding oracles — CVE-2026-13182 and CVE-2026-13183.
Vulnerabilities
8.1
CVE-2026-13181
7.5
CVE-2026-13182
7.5
CVE-2026-13183
7.5
CVE-2026-13184
Researchers
Marcio Almeida
Justin Steven
Vendors
Telerik
Progress
Products
Radasyncupload
System.Configuration.Install.Assemblyinstaller
Telerik_Research
Telerik Ui For Asp.Net Ajax