hacker-news · Crawled Sep 7, 2026

Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released

2 IoCs
Read original article ↗

AI Summary

A public proof-of-concept exploit has been released that chains multiple vulnerabilities in Telerik UI for ASP.NET AJAX to achieve unauthenticated remote code execution. The attack chain leverages a padding oracle (CVE-2026-13182) to decrypt and forge encrypted state, leading to type confusion and deserialization of a malicious mixed-mode DLL via an unguarded type resolution flaw (CVE-2026-13181). Successful exploitation requires non-default configurations, including use of a custom encryption key and presence of the RadAsyncUpload control. While no confirmed in-the-wild exploitation has been reported, the release of working tooling increases risk for misconfigured systems.

AI-extracted · verify before operational use

Indicators of Compromise 2 extracted

Type Value Detail
GitHub Repo telerik-rau-exploit Details →
Filename telerik-rau-exploit Details →