CVE-2026-86157

Summary

Exposure of privileged IPC functionality in Progress Telerik Fiddler Everywhere before version 8.2.0 allows a local, low-privileged attacker who can modify application launch parameters and persuade a user to start the application to replace the application UI or settings with attacker-controlled content. Successful exploitation could result in disclosure of OAuth authentication tokens, execution of locally accessible programs, or unauthorized modification of application-generated configuration files.

Affected Software

VendorProductVersion RangeStatus
Progress SoftwareProgress® Telerik® Fiddler® Everywhere1.0.0 < 8.2.0affected

Weaknesses

  • CWE-749: CWE-749 Exposed Dangerous Method or Function

Workarounds

<div>Users should verify that <b>Fiddler Everywhere</b> shortcuts have not been modified with additional command-line arguments, verify the configured browser executable path, and avoid using application-generated authentication links when manual authentication is available.</div>

References