BE-2026-0004: Potential RCE in AssetWise Inspections Server via Telerik Dependency
Bentley ID: BE-2026-0004
CVE ID: CVE-2026-18672, CVE-2026-19219
Severity: 8.1
CVSS v3.1: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Publication date: 2026-09-02
Revision date: 2026-09-02
Summary
Assetwise Inspections server application includes a potentially vulnerable dependency that, in certain circumstances, could allow an unauthenticated remote attacker to achieve Remote Code Execution (RCE) on the server hosting the application.
Details
AssetWise Inspections uses Telerik's AJAX toolset as part of the solution. In some circumstances this toolkit's Image Editor could potentially allow an unauthenticated remote attacker, who successfully exploits this vulnerability, to execute arbitrary code on the web server with the privileges of the application pool identity. This may result in full server compromise, data exfiltration, or further lateral movement within the hosting environment.
Affected Versions
| Applications | Affected Versions | Mitigated Versions |
|
AssetWise Inspections Server
|
<26.00.08.108
|
>=26.00.08.108
|
Recommended Mitigations
Acknowledgement
Revision History
| Date | Description |
| 2026-09-02 | First version of this advisory |
