Executive brief
Progress Sitefinity, a content management system used to build and manage websites, contains a security flaw in its web services component. An unauthenticated attacker can bypass access controls to view or modify restricted content. This could lead to a complete compromise of the website, including the theft of sensitive data or unauthorized changes to site content.
Technical details
An improper access control vulnerability (CWE-284) exists in the web services component of Progress Sitefinity versions 15.4.8623 through 15.4.8629. The flaw allows a remote, unauthenticated attacker to bypass security restrictions and access protected content. Successful exploitation can result in a full compromise of the affected installation, including unauthorized data access and modification. The vulnerability is addressed in Sitefinity version 15.4.8630.
Affected products
- Progress Sitefinity 15.4.8623 before 15.4.8630
Timeline
- 2026-06-02: advisory: NVD and Progress published the advisory.