Sceawere
Vulnerability Detail
CVE-2026-106145UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Telerik Report Server Privilege Escalation
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 3h ago
- Vendor
- Progress Software
- Product
- Telerik Report Server
- Attack Type
- CWE-266 Incorrect Privilege Assignment
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
In Progress® Telerik® Report Server prior to version 12.2.26.1007, incorrect privilege assignment in the service-agent SignalR hub allows an authenticated user, including a low-privilege or guest account with a valid bearer token, to register as a trusted service agent. On the next server settings-synchronization event, the rogue agent receives storage settings and encryption private keys. This privilege escalation enables disclosure of protected secrets, including stored data-source credentials and connection strings, and allows agent impersonation and interference with task dispatch.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-10-09T08:16:54.250Z",
"pubdate": "2026-10-09T08:16:54.250Z",
"executiveSummary": "This vulnerability involves an incorrect privilege assignment within the Telerik Report Server service-agent SignalR hub. It affects all versions prior to 12.2.26.1007.\nThe flaw allows any authenticated user, including those with minimal privileges or guest status, to successfully register as a trusted service agent. This represents a critical privilege escalation vulnerability.\nBy registering as a rogue agent, an attacker can intercept highly sensitive information during the server settings-synchronization event. This includes the acquisition of storage configuration data and private encryption keys.\nThe potential impact is severe, encompassing the unauthorized disclosure of data-source credentials and connection strings. Furthermore, the attacker gains the ability to impersonate legitimate service agents and interfere with task dispatch processes.\nExploitation requires a valid bearer token, meaning the attacker must be authenticated to the Telerik Report Server environment. Once authenticated, the attacker can leverage the flaw to gain unauthorized access to administrative-level secrets and operational control over the server's task management system.",
"technicalDetails": "The root cause of this vulnerability lies in an insecure authorization check within the service-agent SignalR hub in Telerik Report Server versions prior to 12.2.26.1007. The application fails to properly validate the authorization claims or identity context of a client attempting to initiate an agent registration request.\nThe SignalR hub, responsible for maintaining real-time communication between the report server and its registered agents, does not enforce appropriate access control policies. Consequently, when an authenticated user—regardless of their assigned role—invokes the registration method within the SignalR hub, the system fails to verify whether the requester possesses the required 'Service Agent' or administrative privileges.\nThe exploitation flow proceeds as follows: First, an attacker obtains a valid bearer token by authenticating as a low-privileged or guest user. Second, the attacker interacts with the SignalR hub interface, specifically targeting the function responsible for agent registration. Because the server does not perform adequate privilege validation, the registration request is accepted, and the attacker's session is registered as a 'trusted' service agent within the server's internal registry.\nOnce the malicious registration is established, the server treats the rogue connection as a legitimate component of the infrastructure. During the next scheduled server settings-synchronization event, the server automatically propagates sensitive configuration data to all registered agents. The rogue agent receives critical artifacts, including storage settings and the private keys used for system encryption.\nThe post-exploitation impact is multifaceted. With the obtained private keys and storage settings, the attacker can decrypt protected information, leading to the unauthorized disclosure of data-source credentials and database connection strings. Additionally, the ability to act as a trusted agent allows the attacker to inject malicious tasks or intercept legitimate tasks dispatched by the server, effectively compromising the integrity and availability of the reporting pipeline. The vulnerability allows for horizontal and vertical privilege escalation, as the attacker effectively elevates their system-level access by masquerading as a trusted service component."
}