Privilege Escalation in Progress Telerik Fiddler Everywhere
CVE-2026-86157

5.6MEDIUM

What is CVE-2026-86157?

A vulnerability in Progress Telerik Fiddler Everywhere prior to version 8.2.0 allows a local attacker with low privileges to manipulate application launch parameters. By persuading a user to initiate the application, the attacker can inject custom UI elements or settings, leading to potential exposure of sensitive OAuth authentication tokens, execution of locally accessible programs, or unauthorized modifications to application-generated configuration files. This issue highlights the importance of securing application launch procedures and user interactions.

Affected Version(s)

Progress® Telerik® Fiddler® Everywhere 1.0.0 < 8.2.0

References

CVSS V3.1

Score:
5.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

whizarre
.