Skip to content
Progress SoftwareCVE-2026-86157

Exposure of privileged IPC functionality in Progress Telerik Fiddler Everywhere...

Medium5.6CVE-2026-86157 · Published Sep 29, 2026 · updated Sep 30, 2026

Exposure of privileged IPC functionality in Progress Telerik Fiddler Everywhere before version 8.2.0 allows a local, low-privileged attacker who can modify application launch parameters and persuade a user to start the application to replace the application UI or settings with attacker-controlled content. Successful exploitation could result in disclosure of OAuth authentication tokens, execution of locally accessible programs, or unauthorized modification of application-generated configuration files.

Progress Software advisory

Affected versions

PackageAffectedFixed in
Progress® Telerik® Fiddler® Everywhere
Product
>= 1.0.0, < 8.2.08.2.0
Details and references

More Progress Software advisories

All Progress Software

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.