CVE-2026-18672

In ProgressĀ® TelerikĀ® UI for AJAX prior to v2026.3.812, insufficient validation of client-supplied state in RadImageEditor may allow an attacker to influence which file is returned by the control's image cache, potentially exposing file contents outside the intended image directories.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-02 11:17

Updated : 2026-09-08 19:20


NVD link : CVE-2026-18672

Mitre link : CVE-2026-18672

CVE.ORG link : CVE-2026-18672


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')