Junglewise Threat Intelligence

CVE-2026-7313: Progress Sitefinity insufficiently protected credentials in web services

CVE-2026-7313 · Severity: high · CVSS 8.7 · Published 2026-06-02

Technologies: Progress Sitefinity. Vendors: Progress.

Executive brief

Progress Sitefinity is a content management system used to build and manage websites. A security flaw in its web services allows an authorized user with back-end access to retrieve plain-text credentials for the Sitefinity Insight service. If exploited, this could allow an attacker to gain unauthorized access to customer analytics and marketing data, potentially compromising sensitive business insights.

Technical details

An 'Insufficiently Protected Credentials' vulnerability (CWE-522) exists in the web services component of Progress Sitefinity. A remote attacker with valid back-end authorization can exploit this flaw to retrieve plain-text credentials used for connecting to the Sitefinity Insight service. Successful exploitation requires the site to have an active integration with Sitefinity Insight and a non-default site configuration. The vulnerability is present in versions 8.0.5700 through 13.3.7652. Security updates have been released by the vendor to address this and other related vulnerabilities.

Affected products

  • Progress Sitefinity 8.0.5700 to 13.3.7652

Timeline

  • 2026-06-02: disclosed
  • 2026-06-02: advisory

References

Related threats