🔐 CVE Alert

CVE-2026-106145

HIGH 7.1

Privilege Escalation in Telerik Report Server Service-Agent Hub

CVSS Score
7.1
EPSS Score
0.0%
EPSS Percentile
0th

In Progress® Telerik® Report Server prior to version 12.2.26.1007, incorrect privilege assignment in the service-agent SignalR hub allows an authenticated user, including a low-privilege or guest account with a valid bearer token, to register as a trusted service agent. On the next server settings-synchronization event, the rogue agent receives storage settings and encryption private keys. This privilege escalation enables disclosure of protected secrets, including stored data-source credentials and connection strings, and allows agent impersonation and interference with task dispatch.

CWE CWE-266
Vendor progress software
Product telerik report server
Published Oct 9, 2026
Stay Ahead of the Next One

Get instant alerts for progress software telerik report server

Be the first to know when new high vulnerabilities affecting progress software telerik report server are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
Low
Availability
None

Affected Versions

Progress Software / Telerik Report Server
0 < 12.2.26.1007

References

NVD ↗ CVE.org ↗ EPSS Data ↗
telerik.com: https://www.telerik.com/report-server/documentation/knowledge-base/kb-security-incorrect-privilege-assignment-cve-2026-106145

Credits

Ivan Ivanov