Progress SoftwareCVE-2026-86158
Progress Telerik Fiddler Everywhere: missing authentication
High7.7CVE-2026-86158 · Published Sep 29, 2026 · updated Sep 30, 2026
Missing authentication in the local .NET backend (Fiddler.WebUi) of Progress Software Fiddler Everywhere 8.0.2 allows a local unauthenticated attacker to mint OAuth tokens and read the machine-in-the-middle root certificate through an unauthenticated localhost HTTP and SignalR RPC channel.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Progress® Telerik® Fiddler® Everywhere Product | >= 1.0.0, < 8.2.0 | 8.2.0 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-306
More Progress Software advisories
All Progress Software| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 29 | Exposure of privileged IPC functionality in Progress Telerik Fiddler Everywhere... | Medium5.6 | 8.2.0 |
| Sep 11 | Progress Software Chef Automate: missing authentication | Critical10.0 | 4.13.520 |
| Sep 2 | Progress Software Telerik UI for ASP.NET AJAX: remote code execution | High8.1 | 2026.3.812 |
| Sep 2 | Progress Software Telerik UI for ASP.NET AJAX: path traversal | High7.5 | 2026.3.812 |
| Aug 17 | Progress Software ShareFile Storage Zones Controller: path traversal | High7.2 | No fix yet |
| Aug 17 | Progress Software ShareFile Storage Zones Controller: unsafe deserialization | High8.0 | No fix yet |