BE-2026-0002: SUPERLOAD
Bentley ID: BE-2026-0002
CVE ID: CVE-2026-13181, CVE-2026-13182, CVE-2026-13183, CVE-2026-13184, CVE-2026-13185, CVE-2026-13186, CVE-2026-13190
Severity: 8.1
CVSS v3.1: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Publication date: 2026-08-05
Revision date: 2026-08-05
Summary
SUPERLOAD application includes a potentially vulnerable dependency that in certain circumstances could allow an unauthenticated remote attacker to achieve Remote Code Execution (RCE) on the server hosting the application
Details
SUPERLOAD use Telerik’s AJAX toolset as part of the solution. In some circumstances this toolkit could potentially allow an unauthenticated remote attacker, who successfully exploits this vulnerability, to execute arbitrary code on the web server with the privileges of the application pool identity. This may result in full server compromise, data exfiltration, or further lateral movement within the hosting environment.
Affected Versions
| Applications | Affected Versions | Mitigated Versions |
|
SUPERLOAD
|
<5.00.00.00
|
>=5.00.00.01
|
Recommended Mitigations
Acknowledgement
Revision History
| Date | Description |
| 2026-08-05 | First version of this advisory |
