Exposed Dangerous Method or Function Vulnerability (CVE-2026-86157)
Description
September 2026 - CVE-2026-86157
- Progress® Telerik® Fiddler Everywhere 8.1.0.
What Are the Impacts
In Progress Telerik Fiddler Everywhere 8.1.0, an Exposed Dangerous Method or Function vulnerability exists. A local, low-privileged attacker who can modify application launch parameters and persuade a user to start the application can replace the application UI with attacker-controlled content. Because Electron context isolation is disabled and privileged IPC functionality is exposed to the renderer, the attacker-controlled UI can invoke backend operations. This may disclose a Telerik Identity OAuth token, launch a local program through the custom browser feature, or write a fixed MCP configuration file to a location accessible to the current user.
Issue
- CWE-749: Exposed Dangerous Method or Function
Solution
We have addressed the issue and strongly recommend upgrading to the fixed version listed below when it becomes available.
| Current Version | Update to |
|---|---|
8.1.0 | 8.2.0 |
Follow the Fiddler Everywhere update instructions for precise instructions. Customers can access product downloads from Product Downloads | Your Account.
Mitigation
Until the fixed version is installed:
- Verify that shortcuts used to start Fiddler Everywhere contain no unexpected command-line arguments.
- Manually sign in to Telerik websites instead of opening authenticated links from the application.
- Verify the configured browser executable before using the instrumented browser feature, or do not use that feature.
- Use the manual setup instructions when configuring an MCP client.
There is no separate mitigation for the disabled Electron context isolation configuration.
Notes
- If you have questions or concerns related to this issue, open a new Technical Support case in Your Account | Support Center. Technical Support is available to customers with an active support plan.
External References
- CVE-2026-86157 (Medium)
CVSS: 5.6 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N)
In Progress Telerik Fiddler Everywhere 8.1.0, an Exposed Dangerous Method or Function vulnerability allows a local, low-privileged attacker who controls the application UI to invoke privileged backend operations, potentially disclosing an OAuth token, launching a local program, or writing a fixed MCP configuration file to a user-accessible location.