CVE-2026-86158: Missing Authentication in the local .NET backend of Progress Telerik Fiddler Everywhere
Missing authentication in the local .NET backend (Fiddler.WebUi) of Progress Software Fiddler Everywhere 8.0.2 allows a local unauthenticated attacker to mint OAuth tokens and read the machine-in-the-middle root certificate through an unauthenticated localhost HTTP and SignalR RPC channel.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Systems running Progress Software Fiddler Everywhere 8.0.2 are exposed to a local unauthenticated attacker. The vulnerable component is the local .NET backend, Fiddler.WebUi, reachable through localhost HTTP and SignalR RPC channels.
What can an attacker do if they exploit it?
An attacker can mint OAuth tokens and read the machine-in-the-middle root certificate. The reported impact includes high confidentiality and integrity impact, with no reported availability impact.
Does exploitation require credentials or user interaction?
No. The provided vector indicates no privileges and no user interaction are required, but attacker access must be local.