CVE-2026-7198: CWE-284: Improper Access Control in web services in Progress Sitefinity
CWE-284: Improper Access Control in web services in Progress Sitefinity 15.4.8623 before 15.4.8630 allows a remote unauthenticated attacker to access content that should be restricted, resulting in full compromise of confidentiality, integrity, and availability of affected installations.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Progress Sitefinityto a version that resolves this vulnerability.Fixed in 15.4.8630
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7198?
The severity of CVE-2026-7198 is rated as critical with a score of 9.8.
How do I fix CVE-2026-7198?
To fix CVE-2026-7198, update Progress Sitefinity to version 15.4.8630 or later.
What type of vulnerability is CVE-2026-7198?
CVE-2026-7198 is an improper access control vulnerability in web services.
Who is affected by CVE-2026-7198?
CVE-2026-7198 affects installations of Progress Sitefinity versions 15.4.8623 and earlier.
What impact does CVE-2026-7198 have?
CVE-2026-7198 can lead to full compromise of confidentiality, integrity, and availability of affected installations.