Junglewise Threat Intelligence

CVE-2026-7312: Progress Sitefinity insufficiently protected credentials in web services

CVE-2026-7312 · Severity: critical · CVSS 10 · Published 2026-06-02

Technologies: Progress Sitefinity. Vendors: Progress.

Executive brief

Progress Sitefinity is a content management system used to build and manage corporate websites. A vulnerability in its web services allows unauthorized individuals to steal plain-text credentials used to connect to the Sitefinity Insight analytics service. If exploited, this could allow an attacker to access sensitive marketing data or compromise integrated services, potentially leading to data exposure or unauthorized operational changes.

Technical details

A CWE-522 (Insufficiently Protected Credentials) vulnerability exists in the web services component of Progress Sitefinity. The flaw allows a remote, unauthenticated attacker to retrieve plain-text credentials used for Sitefinity Insight integration. Exploitation requires the target site to have an active integration with Sitefinity Insight and a non-default site configuration. The vulnerability has been assigned a CVSS 3.1 score of 10.0 due to the potential for high impact on confidentiality and integrity across security scopes. Users are advised to update to patched versions as outlined in the vendor's May 2026 security advisory.

Affected products

  • Progress Sitefinity 14.0.7700 to 14.4.8152, 15.0.8200 to 15.0.8234, 15.1.8300 to 15.1.8335, 15.2.8400 to 15.2.8441, 15.3.8500 to 15.3.8531, 15.4.8600 to 15.4.8630

Timeline

  • 2026-06-02: disclosed
  • 2026-06-02: advisory

References

Related threats