AI Weekly Malaysia

Back to items Summaries

Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released

ID
22096
Status
summarized
Published
07 Sep 2026, 7:20 PM
Fetched
07 Sep 2026, 10:55 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/telerik-ui-padding-oracle-bug-chained.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
4.5
Created
07 Sep 2026, 11:02 PM
Tags
Audience
developers

What happened

TantoSec published a working exploit chain and command-line tool (telerik-rau-exploit) that turns an AES-CBC padding oracle in Telerik UI for ASP.NET AJAX's RadAsyncUpload control into unauthenticated RCE. Progress Software patched the flaws in version 2026.2.708 (released July 8, 2026), but the September 7 disclosure puts a ready-to-run exploit with web shell and in-memory DLL payloads in public hands. Exploitation requires a non-default configuration: a RadAsyncUpload handler reading upload results plus an explicit non-default encryption key — a setting Telerik actually recommends as hardening.

Why it matters

If your ASP.NET app uses Telerik UI's RadAsyncUpload with a custom encryption key and is on any version from 2010.1.309 through 2026.2.519, patch to 2026.2.708 immediately — a public exploit tool now exists. The irony worth noting: the configuration that makes you vulnerable (explicit encryption key) is one Telerik recommends as a hardening step, so teams who followed hardening guidance may be the most exposed.

Discussion angle

The counterintuitive risk here: following vendor hardening advice (setting a custom encryption key) is a precondition for this RCE chain. Discuss how teams should reconcile vendor hardening recommendations with emerging attack research, and whether to audit Telerik RadAsyncUpload deployments even if they believe they're 'hardened.'

Top