CVE-2026-77804
Received Received - Intake

TOCTOU Race Condition in Telerik Fiddler Classic HTTPS Certificate Installation

Vulnerability report for CVE-2026-77804, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: Progress Software Corporation

Description

In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, a time-of-check time-of-use (TOCTOU) race condition exists in the installation of the HTTPS interception root certificate into the Local Computer certificate store. Fiddler writes the certificate to a temporary file in a user-writable location and then launches the external TrustCert helper application, which elevates and imports the certificate from that file. A local threat actor with low privileges who replaces the temporary file between the time it is written and the time the elevated helper reads it can cause an attacker-supplied root certificate to be installed in the Local Computer Trusted Root Certification Authorities store, enabling subsequent interception and modification of TLS-protected traffic on the machine. Successful exploitation requires the user to initiate the certificate trust operation and approve the elevation prompt.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Progress Software Progress® Telerik® Fiddler® Classic 1.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-367 The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-77804 is a Time-of-check Time-of-use (TOCTOU) race condition in Progress Telerik Fiddler Classic for Windows versions before v6.0.20262.10021. It involves a local attacker replacing a temporary HTTPS root certificate file after it is written but before an elevated helper application imports it, allowing malicious certificate installation in the Local Computer Trusted Root store.

Detection Guidance

This vulnerability cannot be directly detected via commands as it involves a race condition during certificate installation. Monitor for unexpected root certificates in the Local Computer Trusted Root Certification Authorities store using certmgr.msc or PowerShell commands like Get-ChildItem -Path Cert:\LocalMachine\Root.

Impact Analysis

An attacker could intercept and modify your TLS-protected traffic, including sensitive data like passwords or financial information. This requires the user to initiate certificate trust and approve elevation, but once exploited, it enables widespread traffic monitoring on the affected machine.

Compliance Impact

This vulnerability could lead to unauthorized interception of sensitive data, violating GDPR's data protection principles and HIPAA's confidentiality requirements. Organizations using affected versions may face compliance breaches and legal consequences.

Mitigation Strategies

Update Fiddler Classic to version v6.0.20262.10021 or later to patch the vulnerability. Avoid initiating certificate trust operations in untrusted environments. Review installed root certificates for unauthorized entries.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-77804. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart