PT-2026-63404 · Progress · Telerik Ui For Ajax
CVE-2026-13190
·
Published
2026-07-22
·
Updated
2026-09-07
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Telerik UI for AJAX versions prior to 2026.2.708
Description
A deserialization issue in the persistence utilities allows unsafe type instantiation from an attacker-influenced persisted state, which can lead to remote code execution. Deserialization is the process of converting a data format, such as JSON or XML, back into an object that a program can use.
Recommendations
Update to version 2026.2.708.
Fix
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Telerik Ui For Ajax