Critical Telerik UI For ASP.Net Ajax Vulnerability Chain: CVE-2026-13181 to CVE-2026-13184

Telerik UI For ASP.Net Ajax Vulnerability Chain
Telerik UI For ASP.Net Ajax Vulnerability Chain

HOC Shorts

A high-severity vulnerability chain in Telerik UI for ASP.NET AJAX (RadAsyncUpload) allows unauthenticated attackers to decrypt internal metadata and trigger Remote Code Execution (RCE).

Recommended action: Upgrade to v2026.2.708 (2026 Q2 SP1) or later.

Summary

Security researchers at TantoSec disclosed a linked set of cryptographic side-channel and metadata processing flaws in Progress Telerik UI for ASP.NET AJAX.

By chaining timing and error oracles with default key fallback mechanisms, an unauthenticated remote attacker can reconstruct internal state signatures and manipulate type handlers to execute arbitrary code on the underlying IIS web server.

Vulnerability Comparison Table

CVE ID Vulnerability Type CVSS v3.1 Core Exploit Mechanism Primary Impact
CVE-2026-13181 Unsafe Type Resolution 8.1 (High) Forged upload metadata manipulates AsyncUploadTypeName instantiation. Remote Code Execution (RCE)
CVE-2026-13182 Error Oracle (Decrypt vs. Parse) 7.5 (High) Distinguishes decryption failures from JSON parse errors. Metadata / Key Leakage
CVE-2026-13183 Timing Side-Channel Oracle 7.5 (High) Server response timing variations reveal cryptographic validity. Byte-by-byte State Decryption
CVE-2026-13184 Hardcoded Key Fallback 7.5 (High) Falls back to static keys when configuration keys are missing. Signature Forgery

How the Exploit Chain Works

1. Reconnaissance & Oracle Probing: Attackers send crafted queries to `Telerik.Web.UI.WebResource.axd`. Response timing and error messages reveal whether payload decryption succeeded.
2. Key & Metadata Recovery: The side-channel oracles (CVE-2026-13182, CVE-2026-13183) allow attackers to decrypt client-state metadata without knowing the secret keys.
3. Payload Forgery: If `ConfigurationHashKey` is omitted, the component falls back to default keys (CVE-2026-13184), allowing valid signature generation.
4. Arbitrary Code Execution: The signed payload overrides `AsyncUploadTypeName` (CVE-2026-13181). Upon processing the upload, the IIS worker process (`w3wp.exe`) instantiates the arbitrary type, triggering RCE.

Telerik Web UI DLL
Telerik Web UI DLL – Image by Tantosec

Actionable Mitigation Checklist

  1. Upgrade Framework Assemblies: Deploy Telerik UI for ASP.NET AJAX v2026.2.708 (2026 Q2 SP1) or higher. This update introduces AES-GCM (Authenticated Encryption), resolving the oracle leakage.
  2. Disable Unused Handlers: If `RadAsyncUpload` isn’t required, disable it in `web.config`:
<appSettings>
<add key="Telerik.Web.DisableAsyncUploadHandler" value="true" />
</appSettings>

3. Enforce Manual MachineKeys: Generate explicit, non-autogenerated MachineKeys in IIS using `HMACSHA256` validation.
4. Rotate Existing Keys: Assume current keys are compromised if vulnerable instances were exposed to the public internet.

Join Our Club

Enter your Email address to receive notifications | Join over Million Followers

Previous Article
Cybersecurity risk assessment

Cybersecurity Risk Assessment: Step-by-Step Guide And Free Template

Next Article
what is sandbox in cybersecurity

What is a Sandbox in Cybersecurity?

Related Posts