Privilege Escalation in Progress Telerik Fiddler Everywhere
CVE-2026-86157
5.6MEDIUM
Key Information:
- Vendor
Progress Software
- Vendor
- CVE Published:
- 29 September 2026
What is CVE-2026-86157?
A vulnerability in Progress Telerik Fiddler Everywhere prior to version 8.2.0 allows a local attacker with low privileges to manipulate application launch parameters. By persuading a user to initiate the application, the attacker can inject custom UI elements or settings, leading to potential exposure of sensitive OAuth authentication tokens, execution of locally accessible programs, or unauthorized modifications to application-generated configuration files. This issue highlights the importance of securing application launch procedures and user interactions.
Affected Version(s)
Progress® Telerik® Fiddler® Everywhere 1.0.0 < 8.2.0