BE-2026-0001: AssetWise Inspections Server
Bentley ID: BE-2026-0001
CVE ID: CVE-2026-13181, CVE-2026-13182, CVE-2026-13183, CVE-2026-13184, CVE-2026-13185, CVE-2026-13186, CVE-2026-13190
Severity: 8.1
CVSS v3.1: AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Publication date: 2026-07-24
Revision date: 2026-07-24
Summary
Assetwise Inspections server application includes a potentially vulnerable dependency that in certain circumstances could allow an unauthenticated remote attacker to achieve Remote Code Execution (RCE) on the server hosting the application.
Details
AssetWise Inspections use Telerik’s AJAX toolset as part of the solution. In some circumstances this toolkit could potentially allow an unauthenticated remote attacker, who successfully exploits this vulnerability, to execute arbitrary code on the web server with the privileges of the application pool identity. This may result in full server compromise, data exfiltration, or further lateral movement within the hosting environment.
Affected Versions
| Applications | Affected Versions | Mitigated Versions |
|
AssetWise Inspections Server
|
<26.00.07.151
|
>=26.00.07.151
|
Recommended Mitigations
Acknowledgement
Revision History
| Date | Description |
| 2026-07-24 | First version of this advisory |