rootpwn

medium · CVSS v3 5.6

CVE-2026-86157

Progress Telerik Fiddler Everywhere before v8.2.0 exposes privileged IPC functionality. A local low‑privileged attacker can manipulate launc

Overview

Progress Telerik Fiddler Everywhere before v8.2.0 exposes privileged IPC functionality. A local low‑privileged attacker can manipulate launch parameters to replace UI or settings, potentially leaking OAuth tokens or executing local code. This vulnerability affects users running the affected version on Windows, Linux, or macOS.

Description

Exposure of privileged IPC functionality in Progress Telerik Fiddler Everywhere before version 8.2.0 allows a local, low-privileged attacker who can modify application launch parameters and persuade a user to start the application to replace the application UI or settings with attacker-controlled content. Successful exploitation could result in disclosure of OAuth authentication tokens, execution of locally accessible programs, or unauthorized modification of application-generated configuration files.

Impact

Confidentiality: OAuth tokens may be disclosed. Integrity: Application settings or configuration files can be altered. Availability: Not directly impacted. Defenders: End‑users and administrators of Fiddler Everywhere installations are at risk if they run the vulnerable version and allow users to launch the app with modified parameters.

Remediation

Upgrade to version 8.2.0 or later. If upgrade not possible, restrict application launch parameters to trusted users, disable IPC or enforce signed binaries, and monitor for unauthorized UI changes.

Risk context

Medium severity; no EPSS data available. Prompt patching recommended to prevent potential token leakage or local code execution.

Affected products

  • Progress Telerik Fiddler Everywhere

Scores

Severity
medium
CVSS v2
5.2
CVSS v3
5.6
CVSS v4
—
EPSS
—

IPC PrivilegeEscalation OAuth ConfigurationTampering Fiddler MediumSeverity LocalAttack

← All CVEs