Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
<div>Users should verify that <b>Fiddler Everywhere</b> shortcuts have not been modified with additional command-line arguments, verify the configured browser executable path, and avoid using application-generated authentication links when manual authentication is available.</div>
Tue, 29 Sep 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Exposure of privileged IPC functionality in Progress Telerik Fiddler Everywhere before version 8.2.0 allows a local, low-privileged attacker who can modify application launch parameters and persuade a user to start the application to replace the application UI or settings with attacker-controlled content. Successful exploitation could result in disclosure of OAuth authentication tokens, execution of locally accessible programs, or unauthorized modification of application-generated configuration files. | |
| Title | Exposure of Privileged IPC Functionality in Progress Telerik Fiddler Everywhere | |
| Weaknesses | CWE-749 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: ProgressSoftware
Published:
Updated: 2026-09-29T06:34:17.555Z
Reserved: 2026-09-05T09:09:32.191Z
Link: CVE-2026-86157
No data.
Status : Received
Published: 2026-09-29T07:16:35.377
Modified: 2026-09-29T07:16:35.377
Link: CVE-2026-86157
No data.
OpenCVE Enrichment
Updated: 2026-09-29T08:00:12Z