Privilege Escalation in Telerik Report Server Service-Agent Hub (CVE-2026-106145)
Description
October 2026 - CVE-2026-106145
- Progress® Telerik® Report Server service-agent SignalR hub.
- Versions
>= 0and< 12.2.26.1007.
What Are the Impacts
In Progress® Telerik® Report Server prior to version 12.2.26.1007, incorrect privilege assignment in the service-agent SignalR hub allows an authenticated user, including a low-privilege or guest account with a valid bearer token, to register as a trusted service agent. On the next server settings-synchronization event, the rogue agent receives storage settings and encryption private keys. This privilege escalation enables disclosure of protected secrets, including stored data-source credentials and connection strings, and allows agent impersonation and interference with task dispatch.
Issue
- CWE-266: Incorrect Privilege Assignment
- CAPEC-233: Privilege Escalation
The hub requires authentication but does not verify that the connecting user is the dedicated service-agent system user. An ordinary authenticated user can therefore connect and register as an agent, acquiring access intended only for trusted workers.
Sensitive settings are delivered on a subsequent synchronization event, not immediately upon connection. Events include server startup, an administrator's storage/configuration save, or a scheduled-task reload. The hub does not provide an agent method to force synchronization. The encrypted key exchange does not prevent disclosure to the rogue agent: that agent is a participant in the exchange and can decrypt the payload sent to it.
Solution
The issue is fixed in version 12.2.26.1007. The Progress Telerik team strongly recommends upgrading to this version or later.
| Current Version | Update to |
|---|---|
>= 0 and < 12.2.26.1007 | >= 12.2.26.1007 |
The fix checks that the caller is the dedicated service-agent system user both when the hub connection is established and when agent information is registered. Non-service-agent users are rejected.
Follow the Report Server upgrade instructions for precise instructions. All customers who have a license for Progress® Telerik® Report Server can access their downloads here: Product Downloads | Your Account.
Notes
- If you have any questions or concerns related to this issue, open a new Technical Support case in Your Account | Support Center. Technical Support is available to customers with an active support plan.
External References
CVE-2026-106145 (High)
CVSS: 7.1
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
In Progress® Telerik® Report Server prior to version 12.2.26.1007, incorrect privilege assignment in the service-agent SignalR hub allows an authenticated user, including a low-privilege or guest account with a valid bearer token, to register as a trusted service agent. On the next server settings-synchronization event, the rogue agent receives storage settings and encryption private keys. This privilege escalation enables disclosure of protected secrets, including stored data-source credentials and connection strings, and allows agent impersonation and interference with task dispatch.