In ProgressĀ® TelerikĀ® UI for AJAX prior to v2026.2.708, applications using cookie-based storage in RadPersistenceManager or RadDockLayout deserialize attacker-controlled cookie content, allowing unauthenticated remote code execution.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Telerik_ui_for_asp.net_ajax | Progress | 2013.1.220 (including) | 2026.2.708 (excluding) |