Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4462 articles · 179515 vulns · 37/41 feeds (7d)
← Back to list
7.5
CVE-2026-13189PATCHED
progress · telerik ui for asp.net ajax

SpellChecker DictionaryLanguage Path Traversal Vulnerability in Telerik UI for ASP.NET AJAX

Description

In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of the language parameter in the spell check handler may allow an attacker to influence server-side file path resolution and trigger unintended server-side requests.

Affected Products

VendorProductVersions
progresstelerik ui for asp.net ajax2011.2.712

References

  • https://www.telerik.com/products/aspnet-ajax/documentation/knowledge-base/kb-security-spellchecker-dictionarylanguage-path-traversal-CVE-2026-13189(vendor-advisory)

Related News (1 articles)

Tier C
VulDB7h ago
CVE-2026-13189 | Progress Telerik UI for ASP.NET AJAX up to 2026.2.707 Spell Check Language server-side request forgery
→ No new info (linked only)
CVSS 3.17.5 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
2026.2.708
CWECWE-36
PublishedJul 22, 2026
Last enriched7h agov2
Trending Score36
Source articles1
Independent1
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-8037EXPKEV
OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF
Trending: 91
HIGHCVE-2026-13184
RadAsyncUpload Default HMAC Key Fallback Vulnerability in Telerik UI for ASP.NET AJAX
Trending: 36
HIGHCVE-2026-13182
RadAsyncUpload Client-State Decrypt-vs-Parse Oracle Vulnerability in Telerik UI for ASP.NET AJAX
Trending: 36
HIGHCVE-2026-13183
RadAsyncUpload Upload Metadata Timing Oracle Vulnerability in Telerik UI for ASP.NET AJAX
Trending: 36
MEDIUMCVE-2026-14865
XXE Denial of Service via RadLayoutBuilder Client State in Telerik UI for ASP.NET AJAX
Trending: 32

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 22, 2026
Discovered by ZDM
Jul 22, 2026
Updated: severity, cvssEstimate, cweIds, description
Jul 22, 2026
Patch Available
Jul 22, 2026

Version History

v2
Last enriched 7h ago
v2Tier C7h ago

Updated severity from HIGH to CRITICAL, added CWE-918 (Server-Side Request Forgery), clarified attack vector as SSRF, and refined description with explicit SSRF vulnerability details.

severitycvssEstimatecweIdsdescription
via VulDB
v17h ago

Initial creation