In Progress® Telerik® UI for AJAX versions 2024.4.1114 through 2026.1.421, the RadFilter control is vulnerable to insecure deserialization when restoring filter state if the state is exposed to the client. If an attacker tampers with this state, a server-side remote code execution is possible.
References
| Link | Resource |
|---|---|
| https://www.telerik.com/products/aspnet-ajax/documentation/knowledge-base/kb-security-deserialization-of-untrusted-data-cve-2026-6023 | Mitigation Vendor Advisory |
Configurations
History
05 May 2026, 18:39
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:progress:telerik_ui_for_asp.net_ajax:*:*:*:*:*:*:*:* | |
| References | () https://www.telerik.com/products/aspnet-ajax/documentation/knowledge-base/kb-security-deserialization-of-untrusted-data-cve-2026-6023 - Mitigation, Vendor Advisory | |
| First Time |
Progress
Progress telerik Ui For Asp.net Ajax |
22 Apr 2026, 08:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-22 08:16
Updated : 2026-05-05 18:39
NVD link : CVE-2026-6023
Mitre link : CVE-2026-6023
CVE.ORG link : CVE-2026-6023
JSON object : View
Products Affected
progress
- telerik_ui_for_asp.net_ajax
CWE
CWE-502
Deserialization of Untrusted Data
