High severity7.1NVD Advisory· Published Oct 9, 2026
CVE-2026-106145
CVE-2026-106145
Description
In Progress® Telerik® Report Server prior to version 12.2.26.1007, incorrect privilege assignment in the service-agent SignalR hub allows an authenticated user, including a low-privilege or guest account with a valid bearer token, to register as a trusted service agent. On the next server settings-synchronization event, the rogue agent receives storage settings and encryption private keys. This privilege escalation enables disclosure of protected secrets, including stored data-source credentials and connection strings, and allows agent impersonation and interference with task dispatch.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <12.2.26.1007
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.