CVE-2026-86158
EUVD-2026-8864929.09.2026, 07:16
Missing authentication in the local .NET backend (Fiddler.WebUi) of Progress Software Fiddler Everywhere 8.0.2 allows a local unauthenticated attacker to mint OAuth tokens and read the machine-in-the-middle root certificate through an unauthenticated localhost HTTP and SignalR RPC channel.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| progress | telerik_fiddler_everywhere | 1.0.0 ≤ 𝑥 < 8.2.0 | CNA |
Common Weakness Enumeration