CVE-2026-86157
5.6 MEDIUMPublished 2026-09-29 · Updated 2026-09-29
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
Exposure of privileged IPC functionality in Progress Telerik Fiddler Everywhere before version 8.2.0 allows a local, low-privileged attacker who can modify application launch parameters and persuade a user to start the application to replace the application UI or settings with attacker-controlled content. Successful exploitation could result in disclosure of OAuth authentication tokens, execution of locally accessible programs, or unauthorized modification of application-generated configuration files.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N
Weaknesses
CWE-749
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2026-18901PoC
- HIGHCVE-2026-25255
- UNSCOREDCVE-2026-61793PoC
- HIGHCVE-2026-68928PoC
- CRITICALCVE-2026-77521PoC
- UNSCOREDCVE-2026-89139PoC
- UNSCOREDCVE-2026-92612PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.