CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-19219

highCVSS 8.1covered by 2 sourcesfirst seen 2026-09-02
In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient integrity protection of dialog request parameters used by the RadEditor file browser may allow an attacker who has obtained certain application encryption key material to alter the folders the file browser reads from, writes to, and uploads into, potentially resulting in remote code execution.

CSIRTS triage

What
Path traversal in RadImageEditor and parameter tampering in DialogHandler UploadPaths functionality.
Who is affected
Telerik UI for ASP.NET AJAX versions before 2026.3.812.
Urgency
Severity unknown; update should be applied as soon as available.
Action
Update Telerik UI for ASP.NET AJAX to version 2026.3.812 or later.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-19219

Get an email if CVE-2026-19219 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (2)

External references

NVD record for CVE-2026-19219

CVE.org record

Embed the live status

CVE-2026-19219 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-19219 status](https://www.csirts.com/badge/CVE-2026-19219)](https://www.csirts.com/cve/CVE-2026-19219)