community.progress.comVendor advisory
https://community.progress.com/s/article/Sitefinity-Security-Advisory-for-Addressing-Security-Vulnerabilities-CVE-2026-7312-CVE-2026-7198-CVE-2026-7195-CVE-2026-7201-CVE-2026-7313-May-2026 CVE-2026-7195
HIGH
CWE-20: Improper Input Validation in web services in Progress Sitefinity
Record summary
CVE-2026-7195 has a selected CVSS score of 8.8 (high).
Description
CWE-20: Improper Input Validation in web services in Progress Sitefinity 14.1.x through 14.3.x, 14.4.x before 14.4.8152, 15.0.x before 15.0.8234, 15.1.x before 15.1.8335, 15.2.x before 15.2.8441, 15.3.x before 15.3.8531, and 15.4.x before 15.4.8630 allows a remote unauthenticated attacker to compromise the integrity and confidentiality of user accounts. Successful exploitation requires user interaction and a non-default site configuration.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 2, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
SitefinityBrowse Progress Software / SitefinityDefault status: unknown | CVE List | 14.1.0 to < 14.4.0 | affected |
| 14.4.8100 to < 14.4.8152 | affected | ||
| 15.0.8200 to < 15.0.8234 | affected | ||
| 15.1.8300 to < 15.1.8335 | affected | ||
| 15.2.8400 to < 15.2.8441 | affected | ||
| 15.3.8500 to < 15.3.8531 | affected | ||
| 15.4.8600 to < 15.4.8630 | affected |
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-7195