🔐 CVE Alert

CVE-2026-106155

HIGH 8.9

Stored Cross-site Scripting (XSS) in Telerik Report Server Web Report Viewers

CVSS Score
8.9
EPSS Score
0.0%
EPSS Percentile
0th

In Progress® Telerik® Report Server prior to version 12.2.26.1007, a stored cross-site scripting vulnerability in the shared reporting engine allows an authenticated report author to embed javascript: or vbscript: URLs in report navigation actions or HTML text box links. When another user views the malicious report and the embedded navigation is triggered, attacker-controlled script can execute in the web report viewer's origin. In a multi-user Report Server deployment, this can enable privilege escalation by performing actions in a higher-privilege user's authenticated session, including an administrator's session.

CWE CWE-79
Vendor progress software
Product telerik report server
Published Oct 9, 2026
Stay Ahead of the Next One

Get instant alerts for progress software telerik report server

Be the first to know when new high vulnerabilities affecting progress software telerik report server are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
High
Availability
Low

Affected Versions

Progress Software / Telerik Report Server
0 < 12.2.26.1007

References

NVD ↗ CVE.org ↗ EPSS Data ↗
telerik.com: https://www.telerik.com/report-server/documentation/knowledge-base/kb-security-improper-neutralization-of-input-cve-2026-106155

Credits

Ivan Ivanov