Sceawere

Vulnerability Detail

CVE-2026-86157UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Telerik Fiddler IPC Privilege Escalation

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.6
Creation Date
18h ago
Vendor
Progress Software
Product
Progress® Telerik® Fiddler® Everywhere
Attack Type
CWE-749 Exposed Dangerous Method or Function
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Exposure of privileged IPC functionality in Progress Telerik Fiddler Everywhere before version 8.2.0 allows a local, low-privileged attacker who can modify application launch parameters and persuade a user to start the application to replace the application UI or settings with attacker-controlled content. Successful exploitation could result in disclosure of OAuth authentication tokens, execution of locally accessible programs, or unauthorized modification of application-generated configuration files.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.6",
  "pubDate": "2026-09-29T07:16:35.377Z",
  "pubdate": "2026-09-29T07:16:35.377Z",
  "executiveSummary": "Progress Telerik Fiddler Everywhere versions prior to 8.2.0 contain a critical vulnerability involving the exposure of privileged Inter-Process Communication (IPC) functionality.\nThe vulnerability is classified as an improper authorization or privilege escalation flaw, allowing a local, low-privileged attacker to perform unauthorized actions by manipulating application startup parameters.\nSuccessful exploitation requires the attacker to influence the application launch environment and induce a legitimate user to initiate the process.\nThe potential impact includes the unauthorized disclosure of sensitive OAuth authentication tokens, the execution of arbitrary locally accessible programs, and the illicit modification of application configuration files.\nThis vulnerability poses a significant risk to the integrity and confidentiality of the user's session and the local environment, as it bypasses intended security boundaries for IPC interaction.\nBecause the attack vector is local, the primary constraint is the attacker's ability to modify launch arguments, effectively transforming a low-privileged account's access into broader control over the application's configuration and security tokens.",
  "technicalDetails": "The root cause of this vulnerability lies in the insecure handling of Inter-Process Communication (IPC) mechanisms within Progress Telerik Fiddler Everywhere versions earlier than 8.2.0. The application exposes privileged IPC interfaces that fail to adequately validate the legitimacy or the origin of incoming requests.\nThe attack vector relies on the manipulation of application launch parameters. A local attacker can modify the environment or the execution arguments passed to the Fiddler Everywhere process during its initialization sequence.\nExploitation follows a specific sequence: First, the attacker identifies the mechanism by which Fiddler manages its IPC endpoints. By altering the application launch parameters, the attacker forces the application to load an attacker-controlled configuration or state file, or redirects IPC traffic to a malicious handler.\nOnce the application is launched with the modified parameters—triggered by a victim user—the application initializes its IPC services while trusting the attacker's supplied configuration. This allows the attacker to hijack the communication flow between the application UI and its privileged background processes.\nBy manipulating the UI or the settings interface through this hijacked IPC channel, the attacker can force the application to operate in a compromised state. This allows for the extraction of sensitive data, specifically OAuth authentication tokens, which are typically managed by the application for proxying operations.\nFurthermore, the vulnerability enables an attacker to influence the execution context, facilitating the execution of locally accessible programs under the security context of the user running the application. This represents a significant escalation of privilege from a low-privileged user account to the execution capabilities of the legitimate Fiddler process.\nThe exposure of configuration files also allows the attacker to inject malicious proxy settings or redirect traffic patterns, effectively performing a man-in-the-middle attack on the user's own traffic through the now-compromised application proxy instance.\nThis vulnerability is strictly limited to local exploitation; it does not require network exposure, as it relies on the internal handling of system processes and inter-process signals."
}
CVE-2026-86157: Telerik Fiddler IPC Privilege Escalation (MEDIUM Severity, CVSS: 5.6) | Sceawere