New to Telerik Report Server? Start a free 30-day trial

Privilege Escalation in Telerik Report Server Service-Agent Hub (CVE-2026-106145)

Updated on Oct 8, 2026

Description

October 2026 - CVE-2026-106145

  • Progress® Telerik® Report Server service-agent SignalR hub.
  • Versions >= 0 and < 12.2.26.1007.

What Are the Impacts

In Progress® Telerik® Report Server prior to version 12.2.26.1007, incorrect privilege assignment in the service-agent SignalR hub allows an authenticated user, including a low-privilege or guest account with a valid bearer token, to register as a trusted service agent. On the next server settings-synchronization event, the rogue agent receives storage settings and encryption private keys. This privilege escalation enables disclosure of protected secrets, including stored data-source credentials and connection strings, and allows agent impersonation and interference with task dispatch.

Issue

  • CWE-266: Incorrect Privilege Assignment
  • CAPEC-233: Privilege Escalation

The hub requires authentication but does not verify that the connecting user is the dedicated service-agent system user. An ordinary authenticated user can therefore connect and register as an agent, acquiring access intended only for trusted workers.

Sensitive settings are delivered on a subsequent synchronization event, not immediately upon connection. Events include server startup, an administrator's storage/configuration save, or a scheduled-task reload. The hub does not provide an agent method to force synchronization. The encrypted key exchange does not prevent disclosure to the rogue agent: that agent is a participant in the exchange and can decrypt the payload sent to it.

Solution

The issue is fixed in version 12.2.26.1007. The Progress Telerik team strongly recommends upgrading to this version or later.

Current VersionUpdate to
>= 0 and < 12.2.26.1007>= 12.2.26.1007

The fix checks that the caller is the dedicated service-agent system user both when the hub connection is established and when agent information is registered. Non-service-agent users are rejected.

Follow the Report Server upgrade instructions for precise instructions. All customers who have a license for Progress® Telerik® Report Server can access their downloads here: Product Downloads | Your Account.

Notes

  • If you have any questions or concerns related to this issue, open a new Technical Support case in Your Account | Support Center. Technical Support is available to customers with an active support plan.

External References

CVE-2026-106145 (High)

CVSS: 7.1

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

In Progress® Telerik® Report Server prior to version 12.2.26.1007, incorrect privilege assignment in the service-agent SignalR hub allows an authenticated user, including a low-privilege or guest account with a valid bearer token, to register as a trusted service agent. On the next server settings-synchronization event, the rogue agent receives storage settings and encryption private keys. This privilege escalation enables disclosure of protected secrets, including stored data-source credentials and connection strings, and allows agent impersonation and interference with task dispatch.