← All CVEs NewScan detects
critical

CVE-2026-13181

Telerik UI for ASP.NET AJAX unsafe type resolution in RadAsyncUpload AsyncUploadTypeName -> remote code execution

Severity
critical
Affected product
Telerik UI for ASP.NET AJAX
Affected versions
Telerik UI for ASP.NET AJAX ≥ 2010.1.309, < 2026.2.708
Fixed in
Telerik UI for ASP.NET AJAX 2026.2.708
Added to NewScan
2026-09-07
Detected by
NewScan — free, self-hosted

How NewScan reports it

COMPONENT VERSION RANGE

NewScan fingerprints Telerik UI for ASP.NET AJAX from its response and reports this CVE when the detected version falls inside the affected range below.

8.1, and the endpoint of the chain a public exploit was released for on 2026-09-07. Forged upload metadata steers AsyncUploadTypeName into attacker-controlled type resolution. Chained by the released 2026-09-07 public exploit: 13182/13183 recover the upload metadata protection, 13184 supplies the key when the app never set one, and 13181 turns the forged metadata into code execution. Version-match only - the RadAsyncUpload handler answers identically on patched and unpatched builds, and none of the four can be confirmed non-destructively. 13183's own mechanism is a timing oracle; THIS row concludes from a version string, never from a response-time delta (docs/signature-packs.md and the daily-cve no-timing rule).

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →