{"id":"CVE-2026-86157","published":"2026-09-29T07:16:35.377","lastModified":"2026-09-29T21:27:41.130","description":"Exposure of privileged IPC functionality in Progress Telerik Fiddler Everywhere before version 8.2.0 allows a local, low-privileged attacker who can modify application launch parameters and persuade a user to start the application to replace the application UI or settings with attacker-controlled content. Successful exploitation could result in disclosure of OAuth authentication tokens, execution of locally accessible programs, or unauthorized modification of application-generated configuration files.","cvssScore":5.6,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N","cwes":["CWE-749"],"vendors":[],"products":[],"references":[{"url":"https://www.telerik.com/fiddler/fiddler-everywhere/documentation/knowledge-base/kb-security-exposed-dangerous-method-or-function-cve-2026-86157.","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}