Junglewise Threat Intelligence

CVE-2026-7198: Progress Sitefinity improper access control in web services

CVE-2026-7198 · Severity: critical · CVSS 9.8 · Published 2026-06-02

Technologies: Progress Sitefinity. Vendors: Progress.

Executive brief

Progress Sitefinity, a content management system used to build and manage websites, contains a security flaw in its web services component. An unauthenticated attacker can bypass access controls to view or modify restricted content. This could lead to a complete compromise of the website, including the theft of sensitive data or unauthorized changes to site content.

Technical details

An improper access control vulnerability (CWE-284) exists in the web services component of Progress Sitefinity versions 15.4.8623 through 15.4.8629. The flaw allows a remote, unauthenticated attacker to bypass security restrictions and access protected content. Successful exploitation can result in a full compromise of the affected installation, including unauthorized data access and modification. The vulnerability is addressed in Sitefinity version 15.4.8630.

Affected products

  • Progress Sitefinity 15.4.8623 before 15.4.8630

Timeline

  • 2026-06-02: advisory: NVD and Progress published the advisory.

References

Related threats