← Vulnerability feed

Vulnerability record · CVE-2024-1801 · published 20 March 2024

CVE-2024-1801: Progress telerik reporting deserialization of untrusted data vulnerability

Progress · Telerik Reporting

In Progress® Telerik® Reporting versions prior to 2024 Q1 (18.0.24.130), a code execution attack is possible by a local threat actor through an insecure deserialization vulnerability.

7.8 CVSS 3.1 High EPSS 0.42% · top 66.0% CWE-502 · Deserialization of untrusted data
7.8CVSS 3.1 base score
0.42%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

In Progress® Telerik® Reporting versions prior to 2024 Q1 (18.0.24.130), a code execution attack is possible by a local threat actor through an insecure deserialization vulnerability.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-1801 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-6096Progress telerik reporting vulnerabilityIn Progress® Telerik® Reporting versions prior to 18.1.24.709, a code execution attack is possible through object injection via an insecure type reso…EPSS 0.86%8.8CVE-2024-7293Progress telerik reporting weak password requirements vulnerabilityIn Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), a password brute forcing attack is possible through weak password requir…EPSS 0.33%8.8CVE-2024-8014Progress telerik reporting vulnerabilityIn Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a code execution attack is possible through object injection via an insecure t…EPSS 0.62%8.8CVE-2024-1856Progress telerik reporting deserialization of untrusted data vulnerabilityIn Progress® Telerik® Reporting versions prior to 2024 Q1 (18.0.24.130), a code execution attack is possible by a remote threat actor through an inse…EPSS 1.1%8.6CVE-2024-4202Progress telerik reporting code injection vulnerabilityIn Progress® Telerik® Reporting versions prior to 2024 Q2 (18.1.24.514), a code execution attack is possible through an insecure instantiation vulner…EPSS 0.27%7.8CVE-2024-8048Progress telerik reporting vulnerabilityIn Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a code execution attack is possible using object injection via insecure expres…EPSS 0.22%7.8CVE-2024-7840Progress telerik reporting command injection vulnerabilityIn Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a command injection attack is possible through improper neutralization of hype…EPSS 0.66%7.8CVE-2024-4200Progress telerik reporting deserialization of untrusted data vulnerabilityIn Progress® Telerik® Reporting versions prior to 2024 Q2 (18.1.24.2.514), a code execution attack is possible by a local threat actor through an ins…EPSS 0.30%

Source: NIST National Vulnerability Database (record CVE-2024-1801), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.