SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-18672

HIGH · CVSS 7.5 EPSS 0.36%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Telerik UI for AJAX versions prior to 2026.3.812 are vulnerable due to inadequate validation of client-supplied state in the RadImageEditor component, which could allow attackers to manipulate the image cache and access unauthorized file contents. This vulnerability poses a significant risk of data exposure, making it critical for organizations using this software to prioritize immediate updates to mitigate potential exploitation. Security teams and developers utilizing Telerik UI should take action to ensure their systems are patched.

CVE
CVE-2026-18672
Severity
HIGH
CVSS
7.5
EPSS
0.36%

Original NVD Description

In ProgressĀ® TelerikĀ® UI for AJAX prior to v2026.3.812, insufficient validation of client-supplied state in RadImageEditor may allow an attacker to influence which file is returned by the control's image cache, potentially exposing file contents outside the intended image directories.