CVE-2026-7201
Progress Sitfinity vulnerability analysis and mitigation

Overview

CVE-2026-7201 is an Authorization Bypass Through User-Controlled Key (CWE-639) vulnerability in the web services component of Progress Sitefinity CMS. It allows a remote authenticated attacker to modify account properties of other users, potentially leading to full account compromise. Affected versions include Sitefinity 15.2.x before 15.2.8441, 15.3.x before 15.3.8531, and 15.4.x before 15.4.8630. The vulnerability was published on June 2, 2026, and assigned a CVSS v3.1 base score of 8.8 (High) by Progress Software Corporation (GitHub Advisory, Progress Advisory).

Technical details

The vulnerability is classified as CWE-639 (Authorization Bypass Through User-Controlled Key), where the Sitefinity web services API fails to enforce proper authorization checks when a user-controlled key (such as a user identifier) is used to reference account records. An authenticated attacker can manipulate this key in API requests to target other users' accounts and modify their properties. Exploitation requires the attacker to have knowledge of values (e.g., user identifiers or GUIDs) that are not typically exposed to low-privileged users, adding a partial barrier but not preventing exploitation by a determined attacker with reconnaissance capabilities. No public proof-of-concept code has been identified at this time (GitHub Advisory, Progress Advisory).

Impact

Successful exploitation allows an authenticated attacker to modify account properties of arbitrary users within the Sitefinity platform, potentially enabling full account takeover. The CVSS scoring reflects high impacts across confidentiality, integrity, and availability, meaning an attacker could access sensitive user data, alter account credentials or roles, and disrupt user access. In enterprise environments, this could facilitate privilege escalation or lateral movement if administrative accounts are targeted (GitHub Advisory, Progress Advisory).

Exploitation steps

  1. Reconnaissance: Authenticate to the target Progress Sitefinity instance with a low-privileged user account. Enumerate accessible web service endpoints that handle user account operations.
  2. Identify user keys: Attempt to discover user identifiers (e.g., GUIDs or numeric IDs) for other accounts through information leakage in API responses, error messages, or other application features accessible to authenticated users.
  3. Craft malicious API request: Construct an HTTP request to the Sitefinity web services API endpoint responsible for modifying account properties, substituting the attacker's own user key with the discovered key of a target user.
  4. Submit the request: Send the crafted request to the server. Due to the missing server-side authorization check, the application processes the modification as if the attacker were the account owner.
  5. Achieve account compromise: Successfully modify the target user's account properties (e.g., email address, password reset fields, or role assignments), enabling account takeover or privilege escalation (GitHub Advisory, Progress Advisory).

Indicators of compromise

  • Network: Unusual authenticated API requests to Sitefinity web service endpoints for account modification, particularly where the user identifier in the request does not match the authenticated session's user ID; repeated API calls targeting multiple different user identifiers from a single session.
  • Logs: Sitefinity application logs showing account property modification events for users other than the authenticated requester; API access log entries with mismatched session user and target user identifiers.
  • Application: Unexpected changes to user account properties (email, password, roles) not initiated by the account owner or an administrator; multiple accounts modified in a short timeframe from a single authenticated session.

Mitigation and workarounds

Progress Software has released patched versions addressing this vulnerability: Sitefinity 15.2.8441 or later, 15.3.8531 or later, and 15.4.8630 or later. Organizations should upgrade to the appropriate patched version immediately. As interim mitigations, administrators should implement network segmentation to restrict authenticated user access to sensitive web service endpoints, monitor account modification activities for unauthorized changes, and enforce the principle of least privilege by restricting access to sensitive account properties based on user roles (Progress Advisory).

Community reactions

The Belgian Centre for Cybersecurity (CCB) issued a warning about multiple critical vulnerabilities in Progress Sitefinity, urging immediate patching (CCB Advisory). The Canadian Centre for Cyber Security also published a security advisory (AV26-552) covering the Progress Sitefinity vulnerabilities (CCCS Advisory). Security media outlets including CyberPress and UnderCodeNews covered the broader set of Sitefinity vulnerabilities, highlighting credential exposure risks. Community discussion has been moderate, with aggregators and threat intelligence platforms tracking the CVE but no significant researcher commentary or social media debate noted.

Additional resources


SourceThis report was generated using AI

Related Progress Sitfinity vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-7198CRITICAL9.8
  • Progress Sitfinity logoProgress Sitfinity
  • cpe:2.3:a:progress:sitefinity
NoYesJun 02, 2026
CVE-2026-7201HIGH8.8
  • Progress Sitfinity logoProgress Sitfinity
  • cpe:2.3:a:progress:sitefinity
NoYesJun 02, 2026
CVE-2026-7195HIGH8.1
  • Progress Sitfinity logoProgress Sitfinity
  • cpe:2.3:a:progress:sitefinity
NoYesJun 02, 2026
CVE-2026-7312HIGH7.5
  • Progress Sitfinity logoProgress Sitfinity
  • cpe:2.3:a:progress:sitefinity
NoYesJun 02, 2026
CVE-2026-7313MEDIUM4.9
  • Progress Sitfinity logoProgress Sitfinity
  • cpe:2.3:a:progress:sitefinity
NoYesJun 02, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management