Progress SoftwareCVE-2026-86157
Exposure of privileged IPC functionality in Progress Telerik Fiddler Everywhere...
Medium5.6CVE-2026-86157 · Published Sep 29, 2026 · updated Sep 30, 2026
Exposure of privileged IPC functionality in Progress Telerik Fiddler Everywhere before version 8.2.0 allows a local, low-privileged attacker who can modify application launch parameters and persuade a user to start the application to replace the application UI or settings with attacker-controlled content. Successful exploitation could result in disclosure of OAuth authentication tokens, execution of locally accessible programs, or unauthorized modification of application-generated configuration files.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Progress® Telerik® Fiddler® Everywhere Product | >= 1.0.0, < 8.2.0 | 8.2.0 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-749
More Progress Software advisories
All Progress Software| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 29 | Progress Telerik Fiddler Everywhere: missing authentication | High7.7 | 8.2.0 |
| Sep 11 | Progress Software Chef Automate: missing authentication | Critical10.0 | 4.13.520 |
| Sep 2 | Progress Software Telerik UI for ASP.NET AJAX: remote code execution | High8.1 | 2026.3.812 |
| Sep 2 | Progress Software Telerik UI for ASP.NET AJAX: path traversal | High7.5 | 2026.3.812 |
| Aug 17 | Progress Software ShareFile Storage Zones Controller: path traversal | High7.2 | No fix yet |
| Aug 17 | Progress Software ShareFile Storage Zones Controller: unsafe deserialization | High8.0 | No fix yet |