CVE-2026-77805
Received Received - Intake

Authenticode Signature Bypass in Telerik Fiddler Classic

Vulnerability report for CVE-2026-77805, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: Progress Software Corporation

Description

In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, the integrity check applied to the external helper tools launched by the application is insufficient. Before executing a helper tool, the application only verifies that the file carries a valid Authenticode signature whose certificate subject name matches a broad allow list of publisher name fragments, rather than verifying that the file is the specific executable shipped with that version of the product. A local threat actor with low privileges who replaces one of these helper executables with any other validly signed binary from an allow-listed publisher can cause the substituted binary to be executed by the application, including with Administrator privileges for the tools that request elevation, resulting in privilege escalation and execution of unintended code. Successful exploitation requires the user to launch the affected external tool and to approve the elevation prompt without noticing that it refers to a different executable.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Progress Software Progress® Telerik® Fiddler® Classic 1.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-347 The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-77805 is a weak executable signature verification vulnerability in Progress Telerik Fiddler Classic for Windows before v6.0.20262.10021. The application checks if helper tools have a valid Authenticode signature matching a broad publisher allow list but does not verify if the file is the exact executable shipped with the product. This allows a local attacker to replace a helper executable with any validly signed binary from an allow-listed publisher, leading to unintended code execution with elevated privileges.

Detection Guidance

Check installed versions of Telerik Fiddler Classic. Compare against v6.0.20262.10021 or later. Inspect helper executables in the installation directory for unexpected modifications or mismatched signatures.

Impact Analysis

An attacker with low privileges could replace a helper tool with a malicious but validly signed binary. When you launch the affected tool and approve the elevation prompt, the malicious binary executes with Administrator privileges, allowing the attacker to run arbitrary code on your system.

Compliance Impact

This vulnerability could potentially impact compliance with standards like GDPR and HIPAA by enabling unauthorized code execution with elevated privileges. If exploited, it may allow attackers to bypass security controls, access sensitive data, or perform actions outside intended permissions, which could violate data protection requirements.

Mitigation Strategies

Update to Telerik Fiddler Classic v6.0.20262.10021 or later. Remove unnecessary helper tools. Monitor for unauthorized executable replacements. Restrict write permissions to application directories.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-77805. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart