CVE-2026-86157: Exposure of Privileged IPC Functionality in Progress Telerik Fiddler Everywhere
Exposure of privileged IPC functionality in Progress Telerik Fiddler Everywhere before version 8.2.0 allows a local, low-privileged attacker who can modify application launch parameters and persuade a user to start the application to replace the application UI or settings with attacker-controlled content. Successful exploitation could result in disclosure of OAuth authentication tokens, execution of locally accessible programs, or unauthorized modification of application-generated configuration files.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Progress Telerik Fiddler Everywhereto a version that resolves this vulnerability.Fixed in 8.2.0
Event History
Frequently Asked Questions
Who is realistically exposed to this issue?
Systems running Progress Telerik Fiddler Everywhere before version 8.2.0 are affected when a local low-privileged attacker can modify the application's launch parameters and can persuade a user to start the application.
What does an attacker need to exploit the vulnerability?
The attacker needs local access with low privileges, the ability to alter application launch parameters, and user interaction to cause the application to be launched. The attack is not described as remotely exploitable.
What could indicate successful exploitation?
Potential indicators include unexpected application UI or settings content, disclosure of OAuth authentication tokens, execution of locally accessible programs, or unauthorized changes to configuration files generated by the application.
What is the available remediation?
Update Progress Telerik Fiddler Everywhere to version 8.2.0 or later. The issue affects versions before 8.2.0.