CVE-2026-77804: Time-of-check Time-of-use (TOCTOU) Race Condition in Root Certificate Installation in Progress® Telerik® Fiddler® Classic

Published Oct 5, 2026
·
Updated

In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, a time-of-check time-of-use (TOCTOU) race condition exists in the installation of the HTTPS interception root certificate into the Local Computer certificate store. Fiddler writes the certificate to a temporary file in a user-writable location and then launches the external TrustCert helper application, which elevates and imports the certificate from that file. A local threat actor with low privileges who replaces the temporary file between the time it is written and the time the elevated helper reads it can cause an attacker-supplied root certificate to be installed in the Local Computer Trusted Root Certification Authorities store, enabling subsequent interception and modification of TLS-protected traffic on the machine. Successful exploitation requires the user to initiate the certificate trust operation and approve the elevation prompt.

Affected Software

1 affected component
Progress Telerik Fiddler Classic for Windows<6.0.20262.10021

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Progress Telerik Fiddler Classic for Windows to a version that resolves this vulnerability.

    Fixed in 6.0.20262.10021

Event History

Oct 5, 2026
CVE Published
via MITRE·12:40 PM
Data Sourced
via MITRE·12:40 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to exploitation?

Systems running Progress Telerik Fiddler Classic for Windows before v6.0.20262.10021 are exposed when a user initiates the HTTPS interception root certificate trust operation. The attacker must already have low-privileged local access to the machine.

2

Does exploitation require user interaction or elevation approval?

Yes. A user must start the certificate trust operation and approve the elevation prompt for the TrustCert helper application. The attacker must replace the temporary certificate file before the elevated helper reads it.

3

What is the impact if exploitation succeeds?

An attacker-supplied root certificate can be installed in the Local Computer Trusted Root Certification Authorities store. This can enable later interception and modification of TLS-protected traffic on that machine.

4

How can I determine whether a system is affected?

Check whether Progress Telerik Fiddler Classic for Windows is installed at a version earlier than v6.0.20262.10021. Also review the Local Computer Trusted Root Certification Authorities store for unexpected root certificates if the certificate trust operation may have been performed on a system accessible to low-privileged local users.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203