LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2024-4358: Progress Telerik Report Server Authentication Bypass by Spoofing Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jun 13, 2024
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jul 4, 2024
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2024-4358 to its Known Exploited Vulnerabilities catalog on Jun 13, 2024, with a federal patch deadline of Jul 4, 2024 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Progress Telerik Report Server contains an authorization bypass by spoofing vulnerability that allows an attacker to obtain unauthorized access.

CVE-2024-4358 is an authentication bypass by spoofing vulnerability in Progress Telerik Report Server. It allows an attacker to obtain unauthorized access to the product. For IT and security teams, this matters because Report Server often holds or generates sensitive business reports; unauthorized access can lead to data exposure, further lateral movement, or misuse of reporting capabilities. Confirm all product-specific details against the vendor advisory before acting.

How it works

The flaw is classified as CWE-290, Authentication Bypass by Spoofing. In this class of weakness, an attacker can spoof or forge authentication-related information so that the system incorrectly treats the request as legitimate. The CISA summary states that Progress Telerik Report Server contains an authorization bypass by spoofing vulnerability that allows an attacker to obtain unauthorized access. Public detail on exact request formats, headers, or parameters is limited; defenders should treat any unauthenticated or weakly authenticated interface to the Report Server as potentially abusable until the vendor advisory is reviewed. Successful abuse grants the attacker a foothold with the privileges the spoofed identity would normally hold, without needing valid credentials.

Am I affected? How to find it in your systems

Progress Telerik Report Server is typically deployed as a dedicated reporting service, often on Windows servers or in internal application tiers that generate, store, or serve business reports. It may be exposed to internal users, partner portals, or (less commonly) the internet. Inventory steps:

If the product is present, treat it as potentially vulnerable until the advisory confirms otherwise.

How to remediate

Patch first. Apply the vendor update or mitigations named in the Progress advisory for CVE-2024-4358. CISA’s required action is to apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. After patching:

Document the change and update asset inventories so future scans correctly reflect the remediated state.

If you can't patch immediately

Until the vendor update can be applied, reduce risk with compensating controls:

These measures lower likelihood and impact but do not replace the vendor patch.

If your data may have been exposed

Vulnerabilities that grant unauthorized access can lead to data breaches if exploited. Known ransomware use associated with this CVE is not documented. If you suspect compromise, isolate affected hosts, preserve logs, and begin incident response focused on report data, credentials, and any downstream systems the Report Server could reach. As a quick personal check, individuals can run a free exposure scan of their email address against known breach data sets to see whether their credentials appear in public dumps; organizational teams should perform broader credential and data-exposure reviews. Confirm all findings and next steps against the vendor advisory and your internal incident procedures.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedProgress · Telerik Report Server
WeaknessCWE-290
Added to CISA KEVJun 13, 2024
Federal patch deadlineJul 4, 2024
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities