{"id":"CVE-2026-86158","title":"Missing authentication in the local .NET backend (Fiddler.WebUi) of Progress Software Fiddler Everywhere 8.0.2 allows a local unauthenticated attacker to mint OAuth tokens and read the machine-in-the-middle root certificate through an un…","summary":"Missing authentication in the local .NET backend (Fiddler.WebUi) of Progress Software Fiddler Everywhere 8.0.2 allows a local unauthenticated attacker to mint OAuth tokens and read the machine-in-the-middle root certificate through an un…","severity":"high","cvss":7.7,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","cwe":["CWE-306"],"vendor":"Progress Software","product":"Progress® Telerik® Fiddler® Everywhere","affected":["progress_telerik_fiddler_everywhere >= 1.0.0 < 8.2.0"],"published":"2026-09-29","updated":"2026-09-29","sourceUpdated":"2026-09-29T07:16:35.520","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-86158","references":[{"url":"https://www.telerik.com/fiddler/fiddler-everywhere/documentation/knowledge-base/kb-security-exposed-dangerous-method-or-function-cve-2026-aaaaa","label":"security@progress.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-29T07:29:26.132Z","slug":"CVE-2026-86158","body":"## Overview\n\nMissing authentication in the local .NET backend (Fiddler.WebUi) of Progress Software Fiddler Everywhere 8.0.2 allows a local unauthenticated attacker to mint OAuth tokens and read the machine-in-the-middle root certificate through an unauthenticated localhost HTTP and SignalR RPC channel.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":42,"depthScoreParts":{"impact":42.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}