medium · CVSS v3 5.6
CVE-2026-86157
Progress Telerik Fiddler Everywhere before v8.2.0 exposes privileged IPC functionality. A local low‑privileged attacker can manipulate launc
Overview
Progress Telerik Fiddler Everywhere before v8.2.0 exposes privileged IPC functionality. A local low‑privileged attacker can manipulate launch parameters to replace UI or settings, potentially leaking OAuth tokens or executing local code. This vulnerability affects users running the affected version on Windows, Linux, or macOS.
Description
Exposure of privileged IPC functionality in Progress Telerik Fiddler Everywhere before version 8.2.0 allows a local, low-privileged attacker who can modify application launch parameters and persuade a user to start the application to replace the application UI or settings with attacker-controlled content. Successful exploitation could result in disclosure of OAuth authentication tokens, execution of locally accessible programs, or unauthorized modification of application-generated configuration files.
Impact
Confidentiality: OAuth tokens may be disclosed. Integrity: Application settings or configuration files can be altered. Availability: Not directly impacted. Defenders: End‑users and administrators of Fiddler Everywhere installations are at risk if they run the vulnerable version and allow users to launch the app with modified parameters.
Remediation
Upgrade to version 8.2.0 or later. If upgrade not possible, restrict application launch parameters to trusted users, disable IPC or enforce signed binaries, and monitor for unauthorized UI changes.
Risk context
Medium severity; no EPSS data available. Prompt patching recommended to prevent potential token leakage or local code execution.
Affected products
- Progress Telerik Fiddler Everywhere
Scores
- Severity
- medium
- CVSS v2
- 5.2
- CVSS v3
- 5.6
- CVSS v4
- —
- EPSS
- —