PT-2026-34266 · Progress · Telerik Ui For Ajax

Published

2026-04-22

·

Updated

2026-05-05

·

CVE-2026-6023

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Telerik UI for AJAX versions 2024.4.1114 through 2026.1.421
Description The RadFilter control is subject to insecure deserialization during the restoration of filter state when that state is exposed to the client. An attacker can tamper with this state to achieve server-side remote code execution.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-6023

Affected Products

Telerik Ui For Ajax