CVE-2026-13184
Telerik UI for ASP.NET AJAX predictable default upload-metadata integrity key when Telerik.Upload.ConfigurationHashKey and machineKey are both unset
- Severity
- high
- Affected product
- Telerik UI for ASP.NET AJAX
- Affected versions
- Telerik UI for ASP.NET AJAX ≥ 2010.1.309, < 2026.2.708
- Fixed in
- Telerik UI for ASP.NET AJAX 2026.2.708
- Added to NewScan
- 2026-09-07
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints Telerik UI for ASP.NET AJAX from its response and reports this CVE when the detected version falls inside the affected range below.
A missing-hardening default, so it is reported on the build rather than on the config: whether ConfigurationHashKey or an explicit machineKey is set is not observable from outside. Chained by the released 2026-09-07 public exploit: 13182/13183 recover the upload metadata protection, 13184 supplies the key when the app never set one, and 13181 turns the forged metadata into code execution. Version-match only - the RadAsyncUpload handler answers identically on patched and unpatched builds, and none of the four can be confirmed non-destructively. 13183's own mechanism is a timing oracle; THIS row concludes from a version string, never from a response-time delta (docs/signature-packs.md and the daily-cve no-timing rule).
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →