GHSA-rx77-7xhh-crprHighCVSS 7.7
Missing authentication in the local .NET backend (Fiddler.WebUi) of Progress Software Fiddler...
🔗 CVE IDs covered (1)
📋 Description
Missing authentication in the local .NET backend (Fiddler.WebUi) of Progress Software Fiddler Everywhere 8.0.2 allows a local unauthenticated attacker to mint OAuth tokens and read the machine-in-the-middle root certificate through an unauthenticated localhost HTTP and SignalR RPC channel.
🔗 References (4)
- https://nvd.nist.gov/vuln/detail/CVE-2026-86158
- https://www.telerik.com/fiddler/fiddler-everywhere/documentation/knowledge-base/kb-security-exposed-dangerous-method-or-function-cve-2026-aaaaa
- https://www.telerik.com/fiddler/fiddler-everywhere/documentation/knowledge-base/kb-security-missing-authentication-for-critical-function-cve-2026-86158
- https://github.com/advisories/GHSA-rx77-7xhh-crpr