CVE-2024-4358: Progress Telerik Report Server Authentication Bypass by Spoofing Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2024-06-13. EPSS: 97.5% chance of exploitation in the next 30 days.

In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gain access to Telerik Report Server restricted functionality via an authentication bypass vulnerability.

Affected products

  • Telerik Report Server 2024: up to and including 10.0.24.305

Published 2024-05-29. Last modified 2026-06-17.