Junglewise Threat Intelligence

CVE-2026-7201: Progress Sitefinity authorization bypass in web services

CVE-2026-7201 · Severity: high · CVSS 8.8 · Published 2026-06-02

Technologies: Progress Sitefinity. Vendors: Progress.

Executive brief

Progress Sitefinity is a content management system used to build and manage corporate websites and digital experiences. A security vulnerability in its web services allows an authenticated user to modify the account settings of other users. This could lead to full account takeover, potentially compromising sensitive customer data or site operations, though the attacker must first obtain specific internal identifiers not typically visible to standard users.

Technical details

An authorization bypass vulnerability (CWE-639) exists in Progress Sitefinity web services due to insufficient validation of user-controlled keys. A remote authenticated attacker can exploit this by providing specific identifiers to modify account properties belonging to other users. While the attack requires network access and low-privileged authentication, successful exploitation can lead to complete account compromise. The attacker must have prior knowledge of specific values (such as internal IDs) that are not generally exposed to low-privileged users. The issue is addressed in Sitefinity versions 15.2.8441, 15.3.8531, and 15.4.8630.

Affected products

  • Progress Sitefinity 15.2.x before 15.2.8441, 15.3.x before 15.3.8531, 15.4.x before 15.4.8630

Timeline

  • 2026-06-02: advisory: NVD and vendor advisory published

References

Related threats