CVE-2026-2878

Publication date

2026-02-25 14:45:11

Family

ProgressSoftware

State

PUBLISHED

Description

In ProgressĀ® TelerikĀ® UI for AJAX, versions prior to 2026.1.225, an insufficient entropy vulnerability exists in RadAsyncUpload, where a predictable temporary identifier, based on timestamp and filename, can enable collisions and file content tampering.