CVE-2026-7195 Details
Description
CWE-20: Improper Input Validation in web services in Progress Sitefinity 14.1.x through 14.3.x, 14.4.x before 14.4.8152, 15.0.x before 15.0.8234, 15.1.x before 15.1.8335, 15.2.x before 15.2.8441, 15.3.x before 15.3.8531, and 15.4.x before 15.4.8630 allows a remote unauthenticated attacker to compromise the integrity and confidentiality of user accounts. Successful exploitation requires user interaction and a non-default site configuration.
A vulnerability allowing remote, unauthenticated attackers to compromise the integrity and confidentiality of user accounts has been identified in Progress Sitefinity versions 14.1.x through 14.3.x, 14.4.x prior to 14.4.8152, 15.0.x prior to 15.0.8234, 15.1.x prior to 15.1.8335, 15.2.x prior to 15.2.8441, 15.3.x prior to 15.3.8531, and 15.4.x prior to 15.4.8630. This vulnerability arises from improper input validation in web services, specifically in OData web services, and successful exploitation requires user interaction and a non-default site configuration.
Progress Sitefinity has released product updates for all supported versions. Users are advised to update to the latest version, which is 15.4.8631. For instructions on how to apply the update, refer to the Progress Sitefinity Knowledge Base Article on updating Sitefinity.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 2, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-20 | Improper Input Validation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| progress sitefinity | >= 14.1.7800, < 14.4.8152 >= 15.0.8200, < 15.0.8234 >= 15.1.8300, < 15.1.8335 >= 15.2.8400, < 15.2.8441 >= 15.3.8500, < 15.3.8531 >= 15.4.8600, < 15.4.8630 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 22, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 4, 2026 | Initial Analysis | [email protected] |
| Jun 2, 2026 | New CVE Received | [email protected] |