---
id: CVE-2026-19219
title: >-
  In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient integrity
  protection of dialog request parameters used by the RadEditor file browser may
  allow an attacker who has obtained certain application encryption key material
  …
summary: >-
  In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient integrity
  protection of dialog request parameters used by the RadEditor file browser may
  allow an attacker who has obtained certain application encryption key material
  …
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-345
  - CWE-434
published: '2026-09-02'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T19:20:25.117'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-19219'
references:
  - url: >-
      https://www.telerik.com/products/aspnet-ajax/documentation/knowledge-base/kb-security-dialoghandler-uploadpaths-tampering-cve-2026-19219
    label: security@progress.com
tags:
  - nvd
epss: 0.00157
epssPercentile: 0.04116
ingestedAt: '2026-09-08T20:10:03.160Z'
---

## Overview

In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient integrity protection of dialog request parameters used by the RadEditor file browser may allow an attacker who has obtained certain application encryption key material to alter the folders the file browser reads from, writes to, and uploads into, potentially resulting in remote code execution.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
