Sceawere
Vulnerability Detail
CVE-2026-86158UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Fiddler Everywhere Local Auth Bypass
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.7
- Creation Date
- 18h ago
- Vendor
- Progress Software
- Product
- Progress® Telerik® Fiddler® Everywhere
- Attack Type
- CWE-306: Missing Authentication for Critical Function
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Missing authentication in the local .NET backend (Fiddler.WebUi) of Progress Software Fiddler Everywhere 8.0.2 allows a local unauthenticated attacker to mint OAuth tokens and read the machine-in-the-middle root certificate through an unauthenticated localhost HTTP and SignalR RPC channel.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.7",
"pubDate": "2026-09-29T07:16:35.520Z",
"pubdate": "2026-09-29T07:16:35.520Z",
"executiveSummary": "Progress Software Fiddler Everywhere version 8.0.2 contains a critical vulnerability regarding missing authentication within its local .NET backend (Fiddler.WebUi).\nThe flaw stems from an insecurely exposed localhost HTTP and SignalR RPC channel that lacks proper access controls.\nThis vulnerability allows an unauthenticated local attacker to interface directly with the backend service.\nThe primary security impact includes the unauthorized minting of OAuth tokens and the exfiltration of the machine-in-the-middle root certificate used for traffic interception.\nBecause the interface operates over localhost, exploitation requires a local user or a malicious process running on the host system to interact with the exposed RPC endpoints.\nSuccessful exploitation compromises the integrity of the intercepted traffic environment, enabling the attacker to bypass authentication mechanisms and potentially perform man-in-the-middle attacks on the machine's network traffic.",
"technicalDetails": "The vulnerability resides in the Fiddler.WebUi component of Fiddler Everywhere 8.0.2, which utilizes an internal .NET backend to manage application state and cryptographic assets.\nThe root cause is the absence of authentication enforcement on the RPC interface, which is exposed locally via HTTP and SignalR. By failing to validate the origin or identity of the requester, the application exposes sensitive administrative functions to any process running within the same local security context.\nThe exploitation flow begins when an attacker identifies the port used by the Fiddler.WebUi service on the local machine. Once connected, the attacker leverages the SignalR hub to invoke methods that were intended for internal application use only.\nOne primary vector involves interacting with the OAuth token management functions. Because the service does not perform session validation, an attacker can craft requests to the backend to mint valid OAuth tokens, effectively impersonating the authenticated user or application instance.\nFurthermore, the service provides read access to the machine-in-the-middle (MITM) root certificate. By querying the internal configuration store via the unprotected RPC channel, an attacker can extract the private/public certificate pair used by Fiddler to decrypt TLS traffic. This allows the attacker to install the CA certificate in their own environment to intercept and inspect encrypted traffic passing through the victim's machine.\nThe interaction with the SignalR channel does not require elevated privileges beyond the ability to initiate a network socket to the localhost interface. Consequently, any unprivileged local user can execute these commands, bypassing the security model of the Fiddler application.\nPost-exploitation, the attacker maintains a persistent capability to intercept HTTPS traffic, modify request data, and authenticate as the user to external services, significantly undermining the security of the host's network communications."
}