All Advisories / BE-2026-0001

BE-2026-0001

BE-2026-0001: AssetWise Inspections Server

Bentley ID: BE-2026-0001
CVE ID: CVE-2026-13181, CVE-2026-13182, CVE-2026-13183, CVE-2026-13184, CVE-2026-13185, CVE-2026-13186, CVE-2026-13190
Severity: 8.1
CVSS v3.1: AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Publication date: 2026-07-24
Revision date: 2026-07-24

Summary
Assetwise Inspections server application includes a potentially vulnerable dependency that in certain circumstances could allow an unauthenticated remote attacker to achieve Remote Code Execution (RCE) on the server hosting the application.

Details
AssetWise Inspections use Telerik’s AJAX toolset as part of the solution. In some circumstances this toolkit could potentially allow an unauthenticated remote attacker, who successfully exploits this vulnerability, to execute arbitrary code on the web server with the privileges of the application pool identity. This may result in full server compromise, data exfiltration, or further lateral movement within the hosting environment.

Affected Versions

Applications Affected Versions Mitigated Versions
AssetWise Inspections Server
<26.00.07.151
>=26.00.07.151

 

Recommended Mitigations

Bentley strongly recommends an upgrade to latest versions of AssetWise Inspections Server(web). Please contact Bentley Support for assistance.

Acknowledgement

We would like to thank and acknowledge Telerik for the responsible disclosure.

Revision History

Date Description
2026-07-24 First version of this advisory

20% Off Bentley Software

Deal Ends Friday

Use Coupon Code "THANKS24"