CyberRota Analysis
AI-GeneratedTelerik UI for AJAX versions prior to 2026.2.708 are vulnerable due to insecure deserialization of attacker-controlled cookie content in RadPersistenceManager and RadDockLayout, enabling unauthenticated remote code execution. Organizations utilizing these components in their applications should prioritize patching to mitigate the risk of exploitation. This vulnerability poses a significant threat to any application relying on cookie-based storage for session management.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
In ProgressĀ® TelerikĀ® UI for AJAX prior to v2026.2.708, applications using cookie-based storage in RadPersistenceManager or RadDockLayout deserialize attacker-controlled cookie content, allowing unauthenticated remote code execution.
Related CVEs
Other vulnerabilities affecting the same vendor(s)