Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-77804— Time-of-check Time-of-use (TOCTOU) Race Condition in Root Certificate Installation in Progress® Telerik® Fiddler® Classic

Quick assessment

Affected
Progress Software Progress® Telerik® Fiddler® Classic
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Progress® Telerik® Fiddler® Classic for Windows 的 v6.0.20262.10021 之前的版本中,在安装 HTTPS 拦截根证书到本地计算机证书存储时存在一个检查时-使用时(TOCTOU)竞态条件。Fiddler 将证书写入用户可写位置中的临时文件,然后启动外部 TrustCert 辅助应用程序,该程序以提升权限并从该文件中导入证书。本地低权限威胁参与者在临时文件写入后到提升权限的辅助程序读取该文件之前替换临时文件,可以导致攻击者提供的根证书被安装到本地计算机受

CVSS 6.6 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-77804

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Time-of-check Time-of-use (TOCTOU) Race Condition in Root Certificate Installation in Progress® Telerik® Fiddler® Classic
Source: CVE Program / CVE List V5
Vulnerability Description
In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, a time-of-check time-of-use (TOCTOU) race condition exists in the installation of the HTTPS interception root certificate into the Local Computer certificate store. Fiddler writes the certificate to a temporary file in a user-writable location and then launches the external TrustCert helper application, which elevates and imports the certificate from that file. A local threat actor with low privileges who replaces the temporary file between the time it is written and the time the elevated helper reads it can cause an attacker-supplied root certificate to be installed in the Local Computer Trusted Root Certification Authorities store, enabling subsequent interception and modification of TLS-protected traffic on the machine. Successful exploitation requires the user to initiate the certificate trust operation and approve the elevation prompt.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
检查时间与使用时间(TOCTOU)的竞争条件
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Progress Software Progress® Telerik® Fiddler® Classic 1.0.0 ~ 6.0.20262.10021 -

II. Public POCs for CVE-2026-77804

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-77804

请登录查看更多情报信息。

Other References for CVE-2026-77804 (1)

Same Patch Batch · Progress Software · 2026-10-05 · 5 CVEs total

CVE-2026-92931 8.8 HIGH CWE-918: Server-Side Request Forgery in the Progress Sitefinity Next.js Renderer SDK
CVE-2026-77805 7.9 HIGH Weak Executable Signature Verification Vulnerability in Progress® Telerik® Fiddler® Classi
CVE-2026-77802 6.3 MEDIUM HTTP Request Smuggling Vulnerability in Progress® Telerik® Fiddler® Classic
CVE-2026-77803 3.6 LOW Front-end Desynchronization Vulnerability in Progress® Telerik® Fiddler® Classic

IV. Related Vulnerabilities

V. Comments for CVE-2026-77804

No comments yet


Leave a comment