
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-7201 is an Authorization Bypass Through User-Controlled Key (CWE-639) vulnerability in the web services component of Progress Sitefinity CMS. It allows a remote authenticated attacker to modify account properties of other users, potentially leading to full account compromise. Affected versions include Sitefinity 15.2.x before 15.2.8441, 15.3.x before 15.3.8531, and 15.4.x before 15.4.8630. The vulnerability was published on June 2, 2026, and assigned a CVSS v3.1 base score of 8.8 (High) by Progress Software Corporation (GitHub Advisory, Progress Advisory).
The vulnerability is classified as CWE-639 (Authorization Bypass Through User-Controlled Key), where the Sitefinity web services API fails to enforce proper authorization checks when a user-controlled key (such as a user identifier) is used to reference account records. An authenticated attacker can manipulate this key in API requests to target other users' accounts and modify their properties. Exploitation requires the attacker to have knowledge of values (e.g., user identifiers or GUIDs) that are not typically exposed to low-privileged users, adding a partial barrier but not preventing exploitation by a determined attacker with reconnaissance capabilities. No public proof-of-concept code has been identified at this time (GitHub Advisory, Progress Advisory).
Successful exploitation allows an authenticated attacker to modify account properties of arbitrary users within the Sitefinity platform, potentially enabling full account takeover. The CVSS scoring reflects high impacts across confidentiality, integrity, and availability, meaning an attacker could access sensitive user data, alter account credentials or roles, and disrupt user access. In enterprise environments, this could facilitate privilege escalation or lateral movement if administrative accounts are targeted (GitHub Advisory, Progress Advisory).
Progress Software has released patched versions addressing this vulnerability: Sitefinity 15.2.8441 or later, 15.3.8531 or later, and 15.4.8630 or later. Organizations should upgrade to the appropriate patched version immediately. As interim mitigations, administrators should implement network segmentation to restrict authenticated user access to sensitive web service endpoints, monitor account modification activities for unauthorized changes, and enforce the principle of least privilege by restricting access to sensitive account properties based on user roles (Progress Advisory).
The Belgian Centre for Cybersecurity (CCB) issued a warning about multiple critical vulnerabilities in Progress Sitefinity, urging immediate patching (CCB Advisory). The Canadian Centre for Cyber Security also published a security advisory (AV26-552) covering the Progress Sitefinity vulnerabilities (CCCS Advisory). Security media outlets including CyberPress and UnderCodeNews covered the broader set of Sitefinity vulnerabilities, highlighting credential exposure risks. Community discussion has been moderate, with aggregators and threat intelligence platforms tracking the CVE but no significant researcher commentary or social media debate noted.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."