Time-of-check Time-of-use (TOCTOU) Race Condition in Root Certificate Installation Vulnerability (CVE-2026-77804)
Description
August 2026 - CVE-2026-77804
- Progress® Telerik® Fiddler® Classic 2026 (6.0.20261.7291) or earlier.
What Are the Impacts
In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, an interception and modification of TLS-protected traffic on the machine is possible by installing an attacker-supplied root certificate in the Local Computer Trusted Root Certification Authorities store, leveraging a time-of-check time-of-use (TOCTOU) race condition that exists in the installation of the HTTPS interception root certificate into the Local Computer certificate store. Successful exploitation requires the user to initiate the certificate trust operation and approve the elevation prompt.
Issue
- CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition.
- CAPEC-29: Leveraging Time-of-Check and Time-of-Use (TOCTOU) Race Conditions.
Solution
We have addressed the issue and the Progress Telerik team strongly recommends performing an upgrade to the latest version listed in the table below.
| Current Version | Update to |
|---|---|
>= 1.0.0 && <= 6.0.20261.7291 (2026) | >= 6.0.20262.10021 (2026) |
Follow the update instructions for precise instructions or download the latest version of Progress® Telerik® Fiddler® Classic from this link.
Mitigation
If an immediate upgrade is not possible, apply the following measures to reduce risk:
- Only trust the Fiddler certificate in the current user store from the app. When asked to install it in the local machine store, choose No. Export the certificate to a file and then manually import the file to the local machine store if needed.
Notes
- If you have any questions or concerns related to this issue, open a new Technical Support case in Your Account | Support Center. Technical Support is available to customers with an active support plan.
- We would like to thank NATO Cyber Security Centre (NCSC) for responsibly disclosing this vulnerability.
External References
CVE-2026-77804 (MEDIUM)
CVSS: 6.6
In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, a time-of-check time-of-use (TOCTOU) race condition exists in the installation of the HTTPS interception root certificate into the Local Computer certificate store. Fiddler writes the certificate to a temporary file in a user-writable location and then launches the external TrustCert helper application, which elevates and imports the certificate from that file. A local threat actor with low privileges who replaces the temporary file between the time it is written and the time the elevated helper reads it can cause an attacker-supplied root certificate to be installed in the Local Computer Trusted Root Certification Authorities store, enabling subsequent interception and modification of TLS-protected traffic on the machine. Successful exploitation requires the user to initiate the certificate trust operation and approve the elevation prompt.
Discoverer Credit: NATO Cyber Security Centre (NCSC)