OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-86158

HIGH · CVSS 7.7 EPSS 0.09%

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

The local .NET backend of Progress Software Fiddler Everywhere 8.0.2 is vulnerable due to missing authentication, enabling unauthenticated local attackers to generate OAuth tokens and access the machine-in-the-middle root certificate via an unsecured localhost HTTP and SignalR RPC channel. This vulnerability poses a significant risk as it could lead to unauthorized access and potential manipulation of network traffic. Organizations using this version of Fiddler Everywhere should prioritize remediation to mitigate the risk of local exploitation.

CVE
CVE-2026-86158
Severity
HIGH
CVSS
7.7
EPSS
0.09%

Original NVD Description

Missing authentication in the local .NET backend (Fiddler.WebUi) of Progress Software Fiddler Everywhere 8.0.2 allows a local unauthenticated attacker to mint OAuth tokens and read the machine-in-the-middle root certificate through an unauthenticated localhost HTTP and SignalR RPC channel.