Exposed Dangerous Method or Function Vulnerability (CVE-2026-86157)

Updated on Sep 29, 2026

Description

September 2026 - CVE-2026-86157

  • Progress® Telerik® Fiddler Everywhere 8.1.0.

What Are the Impacts

In Progress Telerik Fiddler Everywhere 8.1.0, an Exposed Dangerous Method or Function vulnerability exists. A local, low-privileged attacker who can modify application launch parameters and persuade a user to start the application can replace the application UI with attacker-controlled content. Because Electron context isolation is disabled and privileged IPC functionality is exposed to the renderer, the attacker-controlled UI can invoke backend operations. This may disclose a Telerik Identity OAuth token, launch a local program through the custom browser feature, or write a fixed MCP configuration file to a location accessible to the current user.

Issue

  • CWE-749: Exposed Dangerous Method or Function

Solution

We have addressed the issue and strongly recommend upgrading to the fixed version listed below when it becomes available.

Current VersionUpdate to
8.1.08.2.0

Follow the Fiddler Everywhere update instructions for precise instructions. Customers can access product downloads from Product Downloads | Your Account.

Mitigation

Until the fixed version is installed:

  • Verify that shortcuts used to start Fiddler Everywhere contain no unexpected command-line arguments.
  • Manually sign in to Telerik websites instead of opening authenticated links from the application.
  • Verify the configured browser executable before using the instrumented browser feature, or do not use that feature.
  • Use the manual setup instructions when configuring an MCP client.

There is no separate mitigation for the disabled Electron context isolation configuration.

Notes

  • If you have questions or concerns related to this issue, open a new Technical Support case in Your Account | Support Center. Technical Support is available to customers with an active support plan.

External References

  • CVE-2026-86157 (Medium)

CVSS: 5.6 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N)

In Progress Telerik Fiddler Everywhere 8.1.0, an Exposed Dangerous Method or Function vulnerability allows a local, low-privileged attacker who controls the application UI to invoke privileged backend operations, potentially disclosing an OAuth token, launching a local program, or writing a fixed MCP configuration file to a user-accessible location.