CVE-2026-6023

In ProgressĀ® TelerikĀ® UI for AJAX versions 2024.4.1114 through 2026.1.421, the RadFilter control is vulnerable to insecure deserialization when restoring filter state if the state is exposed to the client. If an attacker tampers with this state, a server-side remote code execution is possible.
Configurations

Configuration 1 (hide)

cpe:2.3:a:progress:telerik_ui_for_asp.net_ajax:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-04-22 08:16

Updated : 2026-06-17 11:00


NVD link : CVE-2026-6023

Mitre link : CVE-2026-6023

CVE.ORG link : CVE-2026-6023


JSON object : View

Products Affected

progress

  • telerik_ui_for_asp.net_ajax
CWE
CWE-502

Deserialization of Untrusted Data