Improper Input Validation in Progress Sitefinity Web Services
CVE-2026-7195
8.8HIGH
What is CVE-2026-7195?
The vulnerability arises from improper input validation within the web services of Progress Sitefinity. This flaw permits a remote unauthenticated attacker to potentially compromise user account integrity and confidentiality. Exploitation of this vulnerability relies on user interaction as well as a specific non-default site configuration, thereby posing significant risks if left unpatched. Administrators are strongly advised to review site configurations and apply necessary updates to mitigate the threat.
Affected Version(s)
Sitefinity 14.1.0 < 14.4.0
Sitefinity 14.4.8100 < 14.4.8152
Sitefinity 15.0.8200 < 15.0.8234