CVE-2026-14932: Unauthenticated File Read and Deletion via Hardcoded Encryption Key in RadChart
Published Jul 22, 2026
·Updated
In Progress® Telerik® UI for AJAX prior to v2026.2.708, the obsolete RadChart component's ChartImage.axd handler is vulnerable to unauthenticated file read and deletion of image-extension files within the application directory.
Affected Software
1 affected component
Progress Telerik UI for AJAX<2026.2.708
Event History
Jul 22, 2026
CVE Published
via MITRE·01:46 PM
Data Sourced
via MITRE·01:46 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2026-14932?
CVE-2026-14932 is a vulnerability in the RadChart component of Progress Telerik UI for AJAX that allows unauthenticated file read and deletion of files.
2
What is the severity of CVE-2026-14932?
CVE-2026-14932 has a medium severity score of 6.5.
3
How do I fix CVE-2026-14932?
To fix CVE-2026-14932, upgrade to Progress Telerik UI for AJAX version 2026.2.708 or later.
4
What type of files are affected by CVE-2026-14932?
CVE-2026-14932 affects image-extension files within the application directory.
5
What impact does CVE-2026-14932 have on my application?
CVE-2026-14932 may allow attackers to read and delete sensitive files without authentication.