Security Advisory

CVE-2026-18672

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-09-02 10:31:43
Last updated 2026-09-02 10:42:56
Assigner ProgressSoftware
CVSS score 7.5
State PUBLISHED

Description

In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient validation of client-supplied state in RadImageEditor may allow an attacker to influence which file is returned by the control's image cache, potentially exposing file contents outside the intended image directories.