Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 02 Sep 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient validation of client-supplied state in RadImageEditor may allow an attacker to influence which file is returned by the control's image cache, potentially exposing file contents outside the intended image directories. | |
| Title | RadImageEditor ClientState Unauthenticated Arbitrary File Read Vulnerability in Telerik UI for ASP.NET AJAX | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: ProgressSoftware
Published:
Updated: 2026-09-02T10:42:56.527Z
Reserved: 2026-08-03T15:18:25.329Z
Link: CVE-2026-18672
Updated: 2026-09-02T10:42:52.327Z
Status : Received
Published: 2026-09-02T11:17:18.970
Modified: 2026-09-02T11:17:18.970
Link: CVE-2026-18672
No data.
OpenCVE Enrichment
Updated: 2026-09-02T12:30:13Z
-
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')