PatchSiren cyber security CVE debrief
CVE-2026-19219 Progress Software CVE debrief
The CVE-2026-19219 vulnerability exists in Progress Telerik UI for AJAX prior to version 2026.3.812. This vulnerability involves insufficient integrity protection of dialog request parameters used by the RadEditor file browser. An attacker who has obtained certain application encryption key material could potentially alter the folders the file browser reads from, writes to, and uploads into. This could result in remote code execution. Organizations using Progress Telerik UI for AJAX should be aware of this vulnerability and take steps to mitigate it. The CVSS score for this vulnerability is 8.1, indicating a HIGH severity. The CVE record was published on 2026-09-02T11:17:19.270Z and has not been modified since then.
- Vendor
- Progress Software
- Product
- Telerik UI for ASP.NET AJAX
- CVSS
- HIGH 8.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-02
- Original CVE updated
- 2026-09-03
- Advisory published
- 2026-09-02
- Advisory updated
- 2026-09-03
Who should care
Organizations using Progress Telerik UI for AJAX should be aware of this vulnerability and take steps to mitigate it. This includes reviewing and updating application encryption key material management practices and monitoring for suspicious activity related to file browser interactions. The vulnerability has a CVSS score of 8.1, indicating a HIGH severity, and could potentially result in remote code execution if not addressed. Security teams and vulnerability management teams should prioritize patching and review compensating controls for exposed systems while remediation is scheduled and verified. Additionally, asset inventory and monitoring should be reviewed to ensure that affected systems are identified and addressed. Rollback and change windows should also be considered for remediation efforts. Source tracking and exposure review are also recommended to ensure that the vulnerability is properly managed. Defensive priority should be given to patching and mitigating this vulnerability to prevent potential remote code execution. The CVE record was published on 2026-09-02T11:17:19.270Z and has not been modified since then, emphasizing the need for immediate attention to this vulnerability. The vulnerability affects Progress Telerik UI for AJAX, which is a widely used component in various applications, making it a critical vulnerability to address. The insufficient integrity protection of dialog request parameters used by the RadEditor file browser could allow an attacker to alter file browser folders, potentially leading to remote code execution. Therefore, it is essential for organizations to prioritize patching and take steps to mitigate this vulnerability to prevent potential security breaches. The recommended actions include applying the patch (v2026.3.812 or later) for Progress Telerik UI for AJAX, reviewing and updating application encryption key material management practices, and monitoring for suspicious activity related to file browser interactions. By taking these steps, organizations can help prevent potential remote code execution and ensure the security of their systems. The CVE-2026-19219 vulnerability is a critical vulnerability that requires .
Technical summary
The vulnerability exists in Progress Telerik UI for AJAX prior to version 2026.3.812. Insufficient integrity protection of dialog request parameters used by the RadEditor file browser allows an attacker with certain application encryption key material to alter file browser folders, potentially resulting in remote code execution. This vulnerability has a CVSS score of 8.1, indicating a HIGH severity. The CVE record was published on 2026-09-02T11:17:19.270Z and has not been modified since then. Organizations should prioritize patching to prevent potential remote code execution.
Defensive priority
Organizations using Progress Telerik UI for AJAX should prioritize patching to prevent potential remote code execution.
Recommended defensive actions
- Apply the patch (v2026.3.812 or later) for Progress Telerik UI for AJAX to address the insufficient integrity protection vulnerability.
- Review and update application encryption key material management practices.
- Monitor for suspicious activity related to file browser interactions.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Perform asset inventory and monitoring to ensure that affected systems are identified and addressed.
- Consider rollback and change windows for remediation efforts.
- Conduct source tracking and exposure review to ensure that the vulnerability is properly managed.
Evidence notes
The CVE description indicates insufficient integrity protection of dialog request parameters in Progress Telerik UI for AJAX prior to v2026.3.812. An attacker with certain application encryption key material could alter file browser folders, potentially leading to remote code execution. The CVSS score is 8.1 with a HIGH severity.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-19219 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-19219
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-19219 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-19219
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.telerik.com/products/aspnet-ajax/documentation/knowledge-base/kb-security-dialoghandler-uploadpaths-tampering-cve-2026-19219
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.