New to Telerik Report Server? Start a free 30-day trial

Stored Cross-site Scripting in Telerik Report Server Web Report Viewers (CVE-2026-106155)

Updated on Oct 8, 2026

Description

October 2026 - CVE-2026-106155

  • Progress® Telerik® Report Server web report viewers, using the shared reporting engine.
  • Versions >= 0 and < 12.2.26.1007.

What Are the Impacts

In Progress® Telerik® Report Server prior to version 12.2.26.1007, a stored cross-site scripting vulnerability in the shared reporting engine allows an authenticated report author to embed javascript: or vbscript: URLs in report navigation actions or HTML text box links. When another user views the malicious report and the embedded navigation is triggered, attacker-controlled script can execute in the web report viewer's origin. In a multi-user Report Server deployment, this can enable privilege escalation by performing actions in a higher-privilege user's authenticated session, including an administrator's session.

Issue

  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
  • CAPEC-18: XSS Targeting Non-Script Elements

Unsafe URLs reach the viewer through two independent paths. NavigateToUrl actions pass their URLs to interactive viewer navigation or static-export event handlers. Separately, HTML text box anchor elements can include unsafe href attributes in markup copied into the viewer's DOM without passing through the navigation action processor.

The report author controls the stored content, and exploitation requires another user's interaction with the report. The privilege-escalation scenario applies when the victim has greater privileges than the author, particularly when the victim is a Report Server administrator.

Solution

The issue is fixed in version 12.2.26.1007. The Progress Telerik team strongly recommends upgrading to this version or later.

Current VersionUpdate to
>= 0 and < 12.2.26.1007>= 12.2.26.1007

The fix blocks javascript: and vbscript: URLs in both navigation actions and HTML text box links in the shared reporting engine. Validation accounts for case differences and ASCII control/whitespace obfuscation. A client-side navigation guard provides defense in depth. Other URL schemes and relative URLs remain unchanged by this restriction.

Behavior change: Reports that intentionally use javascript: or vbscript: navigation must be revised. These URLs are now blocked across renderers, including desktop viewers where there is no browser-origin XSS.

Follow the Report Server upgrade instructions for precise instructions. All customers who have a license for Progress® Telerik® Report Server can access their downloads here: Product Downloads | Your Account.

Notes

  • If you have any questions or concerns related to this issue, open a new Technical Support case in Your Account | Support Center. Technical Support is available to customers with an active support plan.

External References

CVE-2026-106155 (High)

CVSS: 8.9

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L

In Progress® Telerik® Report Server prior to version 12.2.26.1007, a stored cross-site scripting vulnerability in the shared reporting engine allows an authenticated report author to embed javascript: or vbscript: URLs in report navigation actions or HTML text box links. When another user views the malicious report and the embedded navigation is triggered, attacker-controlled script can execute in the web report viewer's origin. In a multi-user Report Server deployment, this can enable privilege escalation by performing actions in a higher-privilege user's authenticated session, including an administrator's session.