In Progress® Telerik® Report Server prior to version 12.2.26.1007, incorrect privilege assignment in the service-agent SignalR hub allows an authenticated user, including a low-privilege or guest account with a valid bearer token, to register as a trusted service agent. On the next server settings-synchronization event, the rogue agent receives storage settings and encryption private keys. This privilege escalation enables disclosure of protected secrets, including stored data-source credentials and connection strings, and allows agent impersonation and interference with task dispatch.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 09 Oct 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Progress
Progress telerik Report Server |
|
| Vendors & Products |
Progress
Progress telerik Report Server |
Fri, 09 Oct 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Progress® Telerik® Report Server prior to version 12.2.26.1007, incorrect privilege assignment in the service-agent SignalR hub allows an authenticated user, including a low-privilege or guest account with a valid bearer token, to register as a trusted service agent. On the next server settings-synchronization event, the rogue agent receives storage settings and encryption private keys. This privilege escalation enables disclosure of protected secrets, including stored data-source credentials and connection strings, and allows agent impersonation and interference with task dispatch. | |
| Title | Privilege Escalation in Telerik Report Server Service-Agent Hub | |
| Weaknesses | CWE-266 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: ProgressSoftware
Published:
Updated: 2026-10-09T07:03:34.351Z
Reserved: 2026-10-06T15:51:10.392Z
Link: CVE-2026-106145
No data.
Status : Received
Published: 2026-10-09T08:16:54.250
Modified: 2026-10-09T08:16:54.250
Link: CVE-2026-106145
No data.
OpenCVE Enrichment
Updated: 2026-10-09T09:30:03Z
Weaknesses