Sceawere
Vulnerability Detail
CVE-2026-106155UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Telerik Report Server Stored XSS
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.9
- Creation Date
- 3h ago
- Vendor
- Progress Software
- Product
- Telerik Report Server
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
In Progress® Telerik® Report Server prior to version 12.2.26.1007, a stored cross-site scripting vulnerability in the shared reporting engine allows an authenticated report author to embed javascript: or vbscript: URLs in report navigation actions or HTML text box links. When another user views the malicious report and the embedded navigation is triggered, attacker-controlled script can execute in the web report viewer's origin. In a multi-user Report Server deployment, this can enable privilege escalation by performing actions in a higher-privilege user's authenticated session, including an administrator's session.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.9",
"pubDate": "2026-10-09T08:16:54.377Z",
"pubdate": "2026-10-09T08:16:54.377Z",
"executiveSummary": "This vulnerability is a Stored Cross-Site Scripting (XSS) flaw identified in the Telerik Report Server, specifically within its shared reporting engine. The vulnerability affects all versions of the software prior to 12.2.26.1007.\nThe issue arises from insufficient sanitization of URI schemes within report navigation actions and HTML text box links. An authenticated report author can inject malicious 'javascript:' or 'vbscript:' URIs into report objects. When these reports are rendered by other users, the injected script executes within the context of the victim's session.\nThe risk implications are significant in multi-user environments. By targeting administrative users, an attacker can achieve privilege escalation and perform unauthorized actions on behalf of the victim. This vulnerability requires the attacker to hold report authoring privileges, but does not necessitate additional complex exploitation techniques beyond the creation and distribution of a malicious report.\nSuccessful exploitation allows for the execution of arbitrary JavaScript in the victim's browser, potentially leading to full account compromise or unauthorized administrative configuration changes within the Report Server.",
"technicalDetails": "The root cause of this vulnerability is improper input validation and output encoding within the shared reporting engine of Telerik Report Server. The application fails to enforce a strict whitelist of permitted URI schemes when processing user-defined links, such as those found in navigation actions or HTML text box components.\nThe vulnerability is classified as Stored XSS because the malicious payload is persisted within the report's underlying definition. When the reporting engine processes these objects for rendering, it fails to sanitize or neutralize URI schemas such as 'javascript:' or 'vbscript:', effectively allowing the inclusion of executable code in the 'href' attributes of generated HTML elements.\nThe attack flow begins with an authenticated user possessing 'Report Author' privileges. The attacker creates or modifies a report, injecting a malicious URI string into a hyperlink or navigation action. Because the server stores this object without validating the protocol schema, the payload remains dormant until a victim views the report.\nWhen a victim, who may be a high-privileged user or administrator, accesses the malicious report via the web report viewer, the browser interprets the link. Upon interaction with the link—or potentially through automated execution if the navigation is configured to trigger on load—the browser executes the embedded JavaScript within the origin of the Telerik Report Server web application.\nBecause the script executes in the victim's session context, it inherits the victim's authentication tokens and browser session permissions. This enables the attacker to perform cross-site requests to the Report Server API or administrative endpoints. The impact includes, but is not limited to, unauthorized modification of server configurations, data exfiltration, or the creation of additional administrative accounts to ensure persistence.\nThe vulnerability is restricted to versions prior to 12.2.26.1007. It is explicitly dependent on the attacker having legitimate report authoring capabilities, making the attack an internal threat or an escalation from a compromised low-privilege author account."
}