Race Condition Vulnerability in Telerik Fiddler Classic for Windows
CVE-2026-77804

6.6MEDIUM

What is CVE-2026-77804?

A time-of-check time-of-use (TOCTOU) race condition affects Telerik Fiddler Classic for Windows, allowing a local threat actor with low privileges to manipulate the installation of an HTTPS interception root certificate into the Local Computer certificate store. This vulnerability arises when Fiddler writes the certificate to a temporary file in a user-writable location and subsequently initiates the external TrustCert helper application to elevate permissions and import the certificate. If an attacker replaces the temporary file before the helper reads it, they can introduce a malicious root certificate into the Local Computer Trusted Root Certification Authorities store. This facilitates the interception and modification of TLS-protected traffic, provided the user triggers the certificate trust operation and approves the elevation prompt.

Affected Version(s)

Progress® Telerik® Fiddler® Classic Windows 1.0.0 < 6.0.20262.10021

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

NATO Cyber Security Centre (NCSC)
.