Executive brief
Progress Sitefinity is a content management system used to build and manage corporate websites and digital experiences. A security vulnerability in its web services component could allow an attacker to compromise the privacy and integrity of user accounts. To exploit this, an attacker would need to trick a user into performing a specific action on a site with a non-default configuration.
Technical details
An improper input validation vulnerability (CWE-20) exists in the web services component of Progress Sitefinity. The flaw allows a remote, unauthenticated attacker to compromise the integrity and confidentiality of user accounts. The attack vector is network-based, but successful exploitation requires user interaction (UI:R) and is dependent on the site having a non-default configuration. The vulnerability affects multiple versions across the 14.x and 15.x branches. Patches have been released for all supported versions, including 14.4.8152, 15.0.8234, 15.1.8335, 15.2.8441, 15.3.8531, and 15.4.8630.
Affected products
- Progress Sitefinity 14.1.x - 14.3.x, 14.4.x before 14.4.8152, 15.0.x before 15.0.8234, 15.1.x before 15.1.8335, 15.2.x before 15.2.8441, 15.3.x before 15.3.8531, 15.4.x before 15.4.8630
Timeline
- 2026-06-02: disclosed
- 2026-06-02: advisory