CVE-2026-7198: Progress Sitefinity

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

CWE-284: Improper Access Control in web services in Progress Sitefinity 15.4.8623 before 15.4.8630 allows a remote unauthenticated attacker to access content that should be restricted, resulting in full compromise of confidentiality, integrity, and availability of affected installations.

Affected products

  • Progress Sitefinity: from 15.4.8623, before 15.4.8630 (fixed in 15.4.8630)

Published 2026-06-02. Last modified 2026-07-22.