Missing Authentication for Critical Function Vulnerability (CVE-2026-86158)
Description
September 2026 - CVE-2026-86158
- Progress® Telerik® Fiddler® Everywhere versions
>= 1.0.0and<= 8.1.0.
What Are the Impacts
In Progress Telerik Fiddler Everywhere versions prior to 8.2.0, a Missing Authentication for Critical Function vulnerability exists in the local .NET backend (Fiddler.WebUi). A local unauthenticated attacker can connect to the localhost HTTP and SignalR RPC channel and invoke privileged backend operations. This may allow the attacker to mint Telerik Identity OAuth tokens, read the man-in-the-middle root certificate, or access captured session information.
Issue
- CWE-306: Missing Authentication for Critical Function
Solution
We have addressed the issue and strongly recommend upgrading to the fixed version listed below when it becomes available.
| Current Version | Update to |
|---|---|
>= 1.0.0 and <= 8.1.0 | >= 8.2.0 |
Follow the Fiddler Everywhere update instructions for precise instructions. Customers can access product downloads from Product Downloads | Your Account.
Mitigation
There is no mitigation available. Upgrade to version 8.2.0 or later when it becomes available.
Notes
- Progress Software thanks whizarre for reporting this vulnerability.
- If you have questions or concerns related to this issue, open a new Technical Support case in Your Account | Support Center. Technical Support is available to customers with an active support plan.
External References
- CVE-2026-86158 (High)
CVSS: 7.7 (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)
In Progress Telerik Fiddler Everywhere versions prior to 8.2.0, a Missing Authentication for Critical Function vulnerability allows a local unauthenticated attacker to invoke privileged backend operations through the localhost HTTP and SignalR RPC channel, potentially exposing OAuth tokens, the machine-in-the-middle root certificate, and captured session information.