CVE-2026-7198

CRITICAL

CWE-284: Improper Access Control in web services in Progress Sitefinity

Title source: cna
STIX 2.1

Description

CWE-284: Improper Access Control in web services in Progress Sitefinity 15.4.8623 before 15.4.8630 allows a remote unauthenticated attacker to access content that should be restricted, resulting in full compromise of confidentiality, integrity, and availability of affected installations.

Scores

CVSS v3 9.8
EPSS 0.0037
EPSS Percentile 28.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-284
Status published
Products (2)
progress/sitefinity 15.4.8623 - 15.4.8630
Progress Software/Sitefinity 15.4.8623 - 15.4.8630
Published Jun 02, 2026
Tracked Since Jun 02, 2026