CVE-2026-7313: CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity
CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 8.0.5700 to 13.3.7652 allows a remote authenticated attacker to obtain plain-text credentials used connect to Sitefinity Insight service. Successful exploitation requires active integration with Sitefinity Insight, non-default site configuration and valid back-end authorization.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Progress Sitefinityto a version that resolves this vulnerability.Fixed in 13.3.7652 - Compensating control
If Sitefinity Insight integration is not required, do not enable active integration with Sitefinity Insight, since successful exploitation requires active integration with Sitefinity Insight.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7313?
The severity of CVE-2026-7313 is rated high with a score of 8.7.
How do I fix CVE-2026-7313?
To fix CVE-2026-7313, ensure that you apply the latest security patches provided by Progress for Sitefinity.
What type of attack does CVE-2026-7313 allow?
CVE-2026-7313 allows a remote authenticated attacker to obtain plain-text credentials.
Which versions of Progress Sitefinity are affected by CVE-2026-7313?
CVE-2026-7313 affects Progress Sitefinity versions from 8.0.5700 to 13.3.7652.
What is the impact of CVE-2026-7313?
The impact of CVE-2026-7313 is that it exposes insufficiently protected credentials, posing a significant security threat.