{"id":"CVE-2026-86157","title":"Exposure of privileged IPC functionality in Progress Telerik Fiddler Everywhere before version 8.2.0 allows a local, low-privileged attacker who can modify application launch parameters and persuade a user to start the application to rep…","summary":"Exposure of privileged IPC functionality in Progress Telerik Fiddler Everywhere before version 8.2.0 allows a local, low-privileged attacker who can modify application launch parameters and persuade a user to start the application to rep…","severity":"medium","cvss":5.6,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N","cwe":["CWE-749"],"vendor":"Progress Software","product":"Progress® Telerik® Fiddler® Everywhere","affected":["progress_telerik_fiddler_everywhere >= 1.0.0 < 8.2.0"],"published":"2026-09-29","updated":"2026-09-29","sourceUpdated":"2026-09-29T07:16:35.377","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-86157","references":[{"url":"https://www.telerik.com/fiddler/fiddler-everywhere/documentation/knowledge-base/kb-security-exposed-dangerous-method-or-function-cve-2026-86157.","label":"security@progress.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-29T07:29:26.132Z","slug":"CVE-2026-86157","body":"## Overview\n\nExposure of privileged IPC functionality in Progress Telerik Fiddler Everywhere before version 8.2.0 allows a local, low-privileged attacker who can modify application launch parameters and persuade a user to start the application to replace the application UI or settings with attacker-controlled content. Successful exploitation could result in disclosure of OAuth authentication tokens, execution of locally accessible programs, or unauthorized modification of application-generated configuration files.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":31,"depthScoreParts":{"impact":30.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}