Progress Software has patched four vulnerabilities in Telerik Fiddler Classic for Windows, including a high-severity flaw that could allow a local attacker to run unintended code with administrator privileges.
All four vulnerabilities affect Fiddler Classic versions before 6.0.20262.10021. Progress released the fixed Fiddler Classic 6.0.20262 update on Oct. 5 and recommends upgrading affected installations.
The Progress release fixes CVE-2026-77802, CVE-2026-77803, CVE-2026-77804, and CVE-2026-77805. The flaws range from HTTP request handling problems to certificate installation and executable verification weaknesses.
None provides an unauthenticated remote path into Fiddler Classic. Each requires local access or the ability to send traffic through an affected Fiddler instance, and some also require user interaction.
Four vulnerabilities fixed in Fiddler Classic
The most serious issue is CVE-2026-77805, a high-severity weak executable signature verification vulnerability with a CVSS score of 7.9.
According to Progress, Fiddler checks whether external helper tools carry a valid Authenticode signature from an allowed publisher but does not sufficiently verify that the file is the expected executable.
A local attacker with low privileges could replace a helper tool with another validly signed binary from an approved publisher. If the user launches that tool and approves its elevation prompt, the substituted binary can run with administrator privileges, creating a path to privilege escalation and unintended code execution.
CVE-2026-77804, rated 6.6, affects the way Fiddler installs its HTTPS interception root certificate.
The vendor advisory describes a TOCTOU race condition in which Fiddler writes the certificate to a temporary file in a user-writable location before an elevated helper imports it into the Local Computer certificate store.
A low-privilege attacker who replaces that temporary file at the right moment could cause an attacker-controlled root certificate to be trusted by the machine. That certificate could then be used to intercept or modify TLS-protected traffic.
Similar TOCTOU race conditions arise when software checks a file or resource and then uses it later without ensuring it has not changed.
Exploitation still requires the user to initiate the certificate trust operation and approve the elevation prompt.
Two flaws affect Fiddler's HTTP request handling
The remaining vulnerabilities affect how Fiddler forwards HTTP requests.
CVE-2026-77802, rated 6.3, is an HTTP request smuggling vulnerability. Requests containing conflicting Content-Length headers can be interpreted differently by Fiddler and the origin server.
A low-privilege local attacker who can send requests through the same Fiddler proxy as another user could exploit the mismatch against an origin server that does not correctly follow RFC 9110 request handling.
The attack can leave a smuggled response buffered on a reused server connection. That response may then be delivered to another session, potentially exposing information intended for another user or poisoning the response that user receives.
CVE-2026-77803 is a related front-end desynchronization vulnerability rated 3.6.
Progress says a request carrying both Content-Length and Transfer-Encoding headers can be forwarded with both headers intact while Fiddler uses Transfer-Encoding to determine where the request body ends.
Remaining bytes can then be treated as a second request when Fiddler reuses the client connection. A low-privilege local attacker could turn one malformed request into two requests sent to the origin server and receive an additional response.
Unlike CVE-2026-77802, exploitation does not require a vulnerable origin server.
Progress says disabling client connection reuse prevents exploitation of CVE-2026-77803, while disabling server connection reuse mitigates CVE-2026-77802.
What Fiddler Classic users should do
Organizations using Fiddler Classic should upgrade to 6.0.20262.10021 or later.
Progress also provides temporary mitigations for environments where an immediate upgrade is not possible:
- For CVE-2026-77802, disable Reuse server connections under Tools > Options > Connections.
- For CVE-2026-77803, disable Reuse client connections in the same settings menu.
- For CVE-2026-77804, avoid installing Fiddler's root certificate into the Local Computer store through the affected workflow. Progress recommends using the Current User store or manually importing the certificate when machine-wide trust is required.
- For CVE-2026-77805, carefully review elevation prompts and avoid launching Fiddler external tools unless the executable is expected.
The vulnerabilities were disclosed to Progress by the NATO Cyber Security Centre.
None of the four is currently listed in CISA's Known Exploited Vulnerabilities catalog, and Progress's advisories do not report active exploitation.
The local-access requirements reduce exposure compared with an unauthenticated internet-facing vulnerability, but shared development systems and other multi-user Windows environments should still be updated because several of the flaws can cross privilege or user boundaries once an attacker already has local access.
Also read: Defenders managing exposed Windows software should also review the actively exploited Rejetto HFS vulnerability, which can give unauthenticated attackers administrative access and remote code execution.





