MinorCritical vulnerability
CVE-2026-86158 (CVSS 7.7)
NVD · officialPublished Sep 29, 2026Risk 23/100
Missing authentication in the local .NET backend (Fiddler.WebUi) of Progress Software Fiddler Everywhere 8.0.2 allows a local unauthenticated attacker to mint OAuth tokens and read the machine-in-the-middle root certificate through an unauthenticated localhost HTTP and SignalR RPC channel.
Technical details
CVSS
7.7
AV:LocalAC:LowPR:NoneUI:NoneC:HighI:HighA:None
Evidence and sources
This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source