Junglewise Threat Intelligence

CVE-2026-7195: Progress Sitefinity improper input validation in web services

CVE-2026-7195 · Severity: high · CVSS 8.8 · Published 2026-06-02

Technologies: Progress Sitefinity. Vendors: Progress.

Executive brief

Progress Sitefinity is a content management system used to build and manage corporate websites and digital experiences. A security vulnerability in its web services component could allow an attacker to compromise the privacy and integrity of user accounts. To exploit this, an attacker would need to trick a user into performing a specific action on a site with a non-default configuration.

Technical details

An improper input validation vulnerability (CWE-20) exists in the web services component of Progress Sitefinity. The flaw allows a remote, unauthenticated attacker to compromise the integrity and confidentiality of user accounts. The attack vector is network-based, but successful exploitation requires user interaction (UI:R) and is dependent on the site having a non-default configuration. The vulnerability affects multiple versions across the 14.x and 15.x branches. Patches have been released for all supported versions, including 14.4.8152, 15.0.8234, 15.1.8335, 15.2.8441, 15.3.8531, and 15.4.8630.

Affected products

  • Progress Sitefinity 14.1.x - 14.3.x, 14.4.x before 14.4.8152, 15.0.x before 15.0.8234, 15.1.x before 15.1.8335, 15.2.x before 15.2.8441, 15.3.x before 15.3.8531, 15.4.x before 15.4.8630

Timeline

  • 2026-06-02: disclosed
  • 2026-06-02: advisory

References

Related threats