Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-13184

In Progress® Telerik® UI for AJAX prior to v2026.2.708, when Telerik.Upload.ConfigurationHashKey is absent and machineKey is not explicitly configured, upload metadata integrity protection may fall back to a predictable default key, enabling attackers to forge protected upload metadata and unlock further exploit chains.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 10.3%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2026-13184


Contact Us

Shodan ® - All rights reserved