Privilege Escalation Vulnerability in Telerik Fiddler Classic for Windows
CVE-2026-77805

7.9HIGH

What is CVE-2026-77805?

In Telerik Fiddler Classic for Windows, the integrity check for external helper tools is inadequate, allowing a local threat actor to replace a helper executable with a similar signed binary from an allow-listed publisher. This exploited vulnerability can lead to privilege escalation and execution of unintended code when users launch these tools and approve the elevation prompt without recognizing the modified executable.

Affected Version(s)

Progress® Telerik® Fiddler® Classic Windows 1.0.0 < 6.0.20262.10021

References

CVSS V3.1

Score:
7.9
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

NATO Cyber Security Centre (NCSC)
.