Impact
Missing authentication in the local .NET backend (Fiddler.WebUi) allows a local attacker to create OAuth tokens and read the machine‑in‑the‑middle root certificate. This enables the attacker to impersonate the user, intercept traffic, and capture credentials without needing network access or elevated privileges beyond the local account.
Affected Systems
Progress Software’s Fiddler Everywhere version 8.0.2 is vulnerable. The issue resides in the local .NET backend that listens on localhost via HTTP and SignalR RPC.
Risk and Exploitability
The CVSS score of 7.7 indicates a high severity. EPSS is not available, and the vulnerability is not listed in CISA KEV. The attack vector is inferred to be local, requiring the attacker to run code on the same machine or obtain local access. Once the attacker can reach the localhost endpoints, they can freely mint OAuth tokens and read the root certificate, effectively gaining privileged access to intercepted traffic.
OpenCVE Enrichment