
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-7198 is an Improper Access Control (CWE-284) vulnerability in the web services component of Progress Sitefinity CMS that allows remote unauthenticated attackers to access restricted content, resulting in full compromise of confidentiality, integrity, and availability. It affects Progress Sitefinity versions 15.4.8623 through 15.4.8629 (fixed in 15.4.8630). The vulnerability was published on June 2, 2026, by Progress Software Corporation and received initial NVD analysis on June 4, 2026. It carries a CVSS v3.1 base score of 9.8 (Critical) (GitHub Advisory, Progress Advisory).
The vulnerability is classified as CWE-284 (Improper Access Control) and resides in the web services layer of Progress Sitefinity CMS. Due to missing or insufficient authorization enforcement on certain web service endpoints, a remote unauthenticated attacker can send crafted network requests to access content and functionality that should require authentication or elevated privileges. No user interaction or special privileges are required, and the attack complexity is low, making it highly automatable — a fact confirmed by CISA's SSVC assessment marking the vulnerability as "automatable" with "total" technical impact (GitHub Advisory, Progress Advisory). No public proof-of-concept exploit code has been identified at this time (Feedly).
Successful exploitation grants an unauthenticated remote attacker full access to restricted content within the Sitefinity CMS installation, resulting in high impact to confidentiality, integrity, and availability. Attackers may read sensitive data (including potentially stored credentials or user information), modify or delete CMS content, and disrupt service availability. Given that Sitefinity is commonly used in enterprise web environments, exploitation could expose sensitive organizational data and enable further lateral movement within the hosting infrastructure (GitHub Advisory, Feedly).
/api/, /sf/system/, or OData endpoints) from external or unexpected IP addresses; high volume of requests to restricted API paths without corresponding authentication headers.Progress Software has released a patch in Sitefinity version 15.4.8630, which resolves this vulnerability. Organizations running versions 15.4.8623 through 15.4.8629 should upgrade to 15.4.8630 or later immediately (Progress Advisory). As an interim measure where immediate patching is not feasible, apply network segmentation to restrict external access to Sitefinity web service endpoints, and implement web application firewall (WAF) rules to block unauthenticated access to sensitive API paths. Monitor web server and application logs for unauthorized access attempts to restricted content areas.
The Belgium Centre for Cybersecurity (CCB) issued a warning advising organizations to patch immediately, characterizing the vulnerabilities as critical (CCB Advisory). The Canadian Centre for Cyber Security (CCCS) also published a security advisory (AV26-552) covering the Progress Sitefinity vulnerabilities (CCCS Advisory). Security news outlets including SecurityOnline and CyberPress covered the disclosure, with CyberPress noting that the flaws expose credentials to potential silent exploitation (SecurityOnline, CyberPress). The vulnerability was also featured in weekly threat landscape digests, reflecting broad community awareness of the risk.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."