In Progress® Telerik® UI for AJAX prior to v2026.2.708,...
Moderate severity
Unreviewed
Published
Jul 22, 2026
to the GitHub Advisory Database
Description
Published by the National Vulnerability Database
Jul 22, 2026
Published to the GitHub Advisory Database
Jul 22, 2026
In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of content submitted to the RadEditor PDF export feature may allow an authenticated attacker to trigger server-side requests to arbitrary hosts, resulting in outbound network connections and potential exposure of Windows authentication credentials.
References