In Progress® Telerik® UI for AJAX, versions prior to 2026.1.225, an insufficient entropy vulnerability exists in RadAsyncUpload, where a predictable temporary identifier, based on timestamp and filename, can enable collisions and file content tampering.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 25 Feb 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Progress® Telerik® UI for AJAX, versions prior to 2026.1.225, an insufficient entropy vulnerability exists in RadAsyncUpload, where a predictable temporary identifier, based on timestamp and filename, can enable collisions and file content tampering. | |
| Title | Insufficient Entropy Vulnerability in Telerik UI for ASP.NET AJAX | |
| Weaknesses | CWE-331 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: ProgressSoftware
Published:
Updated: 2026-02-25T14:45:11.142Z
Reserved: 2026-02-20T16:20:51.770Z
Link: CVE-2026-2878
No data.
Status : Awaiting Analysis
Published: 2026-02-25T15:20:54.293
Modified: 2026-02-25T15:22:44.317
Link: CVE-2026-2878
No data.
OpenCVE Enrichment
No data.
Weaknesses