← All Advisories

Tampered RadFilter state in Telerik UI for ASP.NET AJAX enables server-side remote code execution

Status: UPDATED  |  Advisory ID: CVE-2026-6023

Key Details

CVECVE-2026-6023
CVSS Score / Version8.1 (High) / CVSS v3.1
CVSS VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is high; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsProgress telerik_ui_for_asp.net_ajax
Classified asCWE-502 (Deserialization of Untrusted Data)
Exploitation prediction (EPSS)0.54% probability of exploitation in the next 30 days (44% percentile) -- FIRST.org's EPSS model.

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Progresstelerik_ui_for_asp.net_ajax
SubsystemsGeneral OT
SectorsMultiple

What to Know

In Progress® Telerik® UI for AJAX versions 2024.4.1114 through 2026.1.421, the RadFilter control is vulnerable to insecure deserialization when restoring filter state if the state is exposed to the client. If an attacker tampers with this state, a server-side remote code execution is possible.

What to Do

Monitor Progress's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-6023
Vendor advisoryhttps://www.telerik.com/products/aspnet-ajax/documentation/knowledge-base/kb-security-deserialization-of-untrusted-data-cve-2026-6023