CVE-2026-19219
Last modified
CVE-2026-19219 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient integrity protection of dialog request parameters used by the RadEditor file browser may allow an attacker who has obtained certain application encryption key material to alter the folders the file browser reads from, writes to, and uploads into, potentially resulting in remote code execution.. EPSS estimates a 0.16% chance of exploitation in the next 30 days.
Description
In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient integrity protection of dialog request parameters used by the RadEditor file browser may allow an attacker who has obtained certain application encryption key material to alter the folders the file browser reads from, writes to, and uploads into, potentially resulting in remote code execution.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Progress Software | Telerik UI for ASP.NET AJAX | >= 2011.2.712, < 2026.3.812 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-19219?
How severe is CVE-2026-19219?
How do I fix CVE-2026-19219?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-1921The Loco Translate plugin for WordPress is vulnerable to Pat…4.9
- CVE-2026-19210A vulnerability has been found in SourceCodester Photo Share…6.3
- CVE-2026-19211A vulnerability was found in SourceCodester Photo Share Webs…7.3
- CVE-2026-19212A vulnerability was determined in WonderTrader up to 0.9.9. …4.3
- CVE-2026-19213A vulnerability was identified in WonderTrader up to 0.9.9. …4.3
- CVE-2026-19217The Royal Addons for Elementor WordPress plugin before 1.7.…5.4
- CVE-2026-1922The The Events Calendar Shortcode & Block plugin for WordPre…6.4
- CVE-2026-19220The Forminator Forms WordPress plugin before 1.57.1 does no…3.7
- CVE-2026-19221The Forminator Forms WordPress plugin before 1.57.0.5 does …7.2
- CVE-2026-19222The Forminator Forms WordPress plugin before 1.57.0.7 does …6.6
- CVE-2026-19223The Smush WordPress plugin before 4.3.2 does not restrict a…7.2
- CVE-2026-19224The Hummingbird Performance WordPress plugin before 3.21.2 …7.2
Are you affected by CVE-2026-19219?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
