CVE-2026-19219
In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient integrity protection of dialog request parameters used by the RadEditor file browser may allow an attacker who has obtained certain application encryption key material to alter the folders the file browser reads from, writes to, and uploads into, potentially resulting in remote code execution.
CSIRTS triage
- What
- Path traversal in RadImageEditor and parameter tampering in DialogHandler UploadPaths functionality.
- Who is affected
- Telerik UI for ASP.NET AJAX versions before 2026.3.812.
- Urgency
- Severity unknown; update should be applied as soon as available.
- Action
- Update Telerik UI for ASP.NET AJAX to version 2026.3.812 or later.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-19219
Get an email if CVE-2026-19219 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Advisory coverage (2)
- unknownProgress Software security advisory (AV26-875)cccs · 2026-09-02
- highCVE-2026-19219: In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient integrity protection of d…nvd · 2026-09-02
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-19219)