CVE-2026-86158
7.7
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Summary
Missing authentication in the local .NET backend (Fiddler.WebUi) of Progress Software Fiddler Everywhere 8.0.2 allows a local unauthenticated attacker to mint OAuth tokens and read the machine-in-the-middle root certificate through an unauthenticated localhost HTTP and SignalR RPC channel.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Progress Software | Progress® Telerik® Fiddler® Everywhere | 1.0.0 < 8.2.0 | affected |
Weaknesses
- CWE-306: CWE-306: Missing Authentication for Critical Function
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.