OFFLINE
Awaiting data
Security intelligence
MinorCritical vulnerability

CVE-2026-86158 (CVSS 7.7)

NVD · officialPublished Sep 29, 2026Risk 23/100

Missing authentication in the local .NET backend (Fiddler.WebUi) of Progress Software Fiddler Everywhere 8.0.2 allows a local unauthenticated attacker to mint OAuth tokens and read the machine-in-the-middle root certificate through an unauthenticated localhost HTTP and SignalR RPC channel.

CVSS
7.7
AV:LocalAC:LowPR:NoneUI:NoneC:HighI:HighA:None

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source