Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released
- ID
- 22096
- Status
- summarized
- Published
- 07 Sep 2026, 7:20 PM
- Fetched
- 07 Sep 2026, 10:55 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/telerik-ui-padding-oracle-bug-chained.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 4.5
- Created
- 07 Sep 2026, 11:02 PM
- Tags
- Audience
- developers
What happened
TantoSec published a working exploit chain and command-line tool (telerik-rau-exploit) that turns an AES-CBC padding oracle in Telerik UI for ASP.NET AJAX's RadAsyncUpload control into unauthenticated RCE. Progress Software patched the flaws in version 2026.2.708 (released July 8, 2026), but the September 7 disclosure puts a ready-to-run exploit with web shell and in-memory DLL payloads in public hands. Exploitation requires a non-default configuration: a RadAsyncUpload handler reading upload results plus an explicit non-default encryption key — a setting Telerik actually recommends as hardening.
Why it matters
If your ASP.NET app uses Telerik UI's RadAsyncUpload with a custom encryption key and is on any version from 2010.1.309 through 2026.2.519, patch to 2026.2.708 immediately — a public exploit tool now exists. The irony worth noting: the configuration that makes you vulnerable (explicit encryption key) is one Telerik recommends as a hardening step, so teams who followed hardening guidance may be the most exposed.
Discussion angle
The counterintuitive risk here: following vendor hardening advice (setting a custom encryption key) is a precondition for this RCE chain. Discuss how teams should reconcile vendor hardening recommendations with emerging attack research, and whether to audit Telerik RadAsyncUpload deployments even if they believe they're 'hardened.'