CVE-2026-106145: Progress Software Telerik Report Server
High severity, CVSS 7.1. EPSS: 0.1% chance of exploitation in the next 30 days.
In Progress® Telerik® Report Server prior to version 12.2.26.1007, incorrect privilege assignment in the service-agent SignalR hub allows an authenticated user, including a low-privilege or guest account with a valid bearer token, to register as a trusted service agent. On the next server settings-synchronization event, the rogue agent receives storage settings and encryption private keys. This privilege escalation enables disclosure of protected secrets, including stored data-source credentials and connection strings, and allows agent impersonation and interference with task dispatch.
Affected products
- Progress Software Telerik Report Server: before 12.2.26.1007 (fixed in 12.2.26.1007)
Published 2026-10-09. Last modified 2026-10-09.