
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-7195 is an Improper Input Validation vulnerability (CWE-20) in the web services component of Progress Sitefinity CMS that allows a remote unauthenticated attacker to compromise the integrity and confidentiality of user accounts. It affects Sitefinity versions 14.1.x through 14.3.x, 14.4.x before 14.4.8152, 15.0.x before 15.0.8234, 15.1.x before 15.1.8335, 15.2.x before 15.2.8441, 15.3.x before 15.3.8531, and 15.4.x before 15.4.8630. The vulnerability was published on June 2, 2026, and is part of a broader May 2026 security advisory from Progress Software covering multiple CVEs. The CVSS v3.1 base score is 8.1 (High) per NVD, and 8.8 (High) per the CNA (Progress Software Corporation) (GitHub Advisory, Progress Advisory).
The root cause is CWE-20 (Improper Input Validation) in Progress Sitefinity's web services layer, where user-supplied input is not adequately validated or sanitized before processing. An unauthenticated remote attacker can craft a malicious request that, when interacted with by a victim user, exploits this flaw to tamper with or access user account data. Exploitation requires two preconditions: user interaction (e.g., a victim clicking a crafted link or visiting a malicious page) and a non-default site configuration on the Sitefinity instance. No specific technical write-up or public proof-of-concept code has been identified at this time (GitHub Advisory, Progress Advisory).
Successful exploitation allows an unauthenticated attacker to compromise both the confidentiality and integrity of user accounts on affected Sitefinity installations, potentially enabling unauthorized access to sensitive user information and modification of account data. Availability is not impacted according to NVD's assessment (CVSS A:N), though the CNA rates availability impact as High. The attack scope is limited to the vulnerable Sitefinity instance, but account compromise could facilitate further unauthorized actions within the CMS environment, including access to managed content and potentially privileged administrative functions (GitHub Advisory, Progress Advisory).
Progress Software has released patched versions addressing CVE-2026-7195. Organizations should upgrade to the following fixed versions based on their current branch: 14.4.8152 or later, 15.0.8234 or later, 15.1.8335 or later, 15.2.8441 or later, 15.3.8531 or later, or 15.4.8630 or later. Note that versions 14.1.x through 14.3.x are fully affected with no patch in that branch — users on those versions should upgrade to 14.4.8152 or a later supported branch. As an additional measure, organizations should review their Sitefinity site configuration to ensure non-default settings that increase attack surface are minimized, and implement input validation controls at the web application firewall level where possible (Progress Advisory, GitHub Advisory).
The Belgian Centre for Cybersecurity (CCB) issued a warning about multiple critical vulnerabilities in Progress Sitefinity, urging organizations to patch immediately. The Canadian Centre for Cyber Security (CCCS) published a security advisory (AV26-552) covering the Progress Sitefinity vulnerabilities. Security news outlets including SecurityOnline and CyberPress covered the disclosure, with CyberPress noting that the flaws expose credentials to potential exploitation. The vulnerability was also discussed in weekly threat landscape digests and threat intelligence aggregators, reflecting moderate community attention given its High severity rating and the broader context of multiple simultaneous Sitefinity CVEs (CCB Advisory, CCCS Advisory, SecurityOnline).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."