rootpwn

high · CVSS v3 7.7

CVE-2026-86158

Progress Software Fiddler Everywhere 8.0.2 contains a missing authentication flaw in its local .NET backend (Fiddler.WebUi) that lets a loca

Overview

Progress Software Fiddler Everywhere 8.0.2 contains a missing authentication flaw in its local .NET backend (Fiddler.WebUi) that lets a local attacker mint OAuth tokens and read the machine‑in‑the‑middle root certificate via an unauthenticated localhost HTTP and SignalR RPC channel.

Description

Missing authentication in the local .NET backend (Fiddler.WebUi) of Progress Software Fiddler Everywhere 8.0.2 allows a local unauthenticated attacker to mint OAuth tokens and read the machine-in-the-middle root certificate through an unauthenticated localhost HTTP and SignalR RPC channel.

Impact

The vulnerability compromises confidentiality by exposing the root certificate used for MITM interception, allowing attackers to decrypt traffic. It also undermines integrity by permitting the creation of valid OAuth tokens, enabling unauthorized access to protected resources. Local users and administrators are the primary impact group, as the flaw requires local execution but can affect any service relying on Fiddler’s authentication.

Remediation

Apply the vendor’s patch or upgrade to a version that enforces authentication on the Fiddler.WebUi backend. Disable or restrict the localhost HTTP and SignalR endpoints if not needed, and enforce network segmentation or firewall rules to limit local access. Monitor for unexpected OAuth token generation and audit logs for unauthorized certificate reads.

Risk context

The CVSS v3 score of 7.7 indicates a high severity risk. No EPSS data is available, but the flaw’s local nature means it can be exploited by any user with local access, warranting prompt remediation.

Affected products

  • Progress Software Fiddler Everywhere 8.0.2
  • Fiddler.WebUi

Scores

Severity
high
CVSS v2
6.6
CVSS v3
7.7
CVSS v4
—
EPSS
—

authentication local OAuth SignalR root-certificate Fiddler high-severity

← All CVEs