HarborGuard / CVE
Back to search
HIGHCVE-2026-6023Published Modified CNA ProgressSoftware

CVE-2026-6023: Deserialization of Untrusted Data Vulnerability in Telerik UI for ASP.NET AJAX

In Progress® Telerik® UI for AJAX versions 2024.4.1114 through 2026.1.421, the RadFilter control is vulnerable to insecure deserialization when restoring filter state if the state is exposed to the client. If an attacker tampers with this state, a server-side remote code execution is possible.

Metrics

CVSS v3.1
8.1
Severity
HIGH
Fixed in
2026.1.421
Affected Products
1

Fix available

2026.1.421
Affected packages
  • Progress Software / Telerik UI for ASP.NET AJAX
    < 2026.1.421 (from 2024.4.1114)
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
References