CVE-2026-7312 Details
Description
CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 14.0.7700 to 14.4.8152, and 15.0.8200 to 15.0.8234, and 15.1.8300 to 15.1.8335, 15.2.8400 to 15.2.8441, 15.3.8500 to 15.3.8531, and 15.4.8600 to 15.4.8630 allows a remote unauthenticated attacker to obtain plain-text credentials used connect to Sitefinity Insight service. Successful exploitation requires active integration with Sitefinity Insight and non-default site configuration.
A vulnerability allowing remote unauthenticated attackers to access plain-text credentials for the Sitefinity Insight service has been identified in Progress Sitefinity. This issue affects versions 14.0.7700 to 14.4.8152, 15.0.8200 to 15.0.8234, 15.1.8300 to 15.1.8335, 15.2.8400 to 15.2.8441, 15.3.8500 to 15.3.8531, and 15.4.8600 to 15.4.8630. The vulnerability arises from insufficient protection of credentials in web services, specifically OData and ServiceStack, and requires active integration with Sitefinity Insight and a non-default site configuration for exploitation.
Progress Sitefinity has released product updates for all supported versions. Users are advised to update to the latest version, 15.4.8631, and can refer to the Progress Sitefinity update guide for instructions on applying the update.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-522 | Insufficiently Protected Credentials | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| progress sitefinity | >= 14.0.7700, < 14.4.8152 >= 15.0.8200, < 15.0.8234 >= 15.1.8300, < 15.1.8335 >= 15.2.8400, < 15.2.8441 >= 15.3.8500, < 15.3.8531 >= 15.4.8600, < 15.4.8630 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 22, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 4, 2026 | Initial Analysis | [email protected] |
| Jun 2, 2026 | New CVE Received | [email protected] |