Insufficiently Protected Credentials in Progress Sitefinity Web Services
CVE-2026-7313

8.7HIGH

Key Information:

Vendor
CVE Published:
2 June 2026

What is CVE-2026-7313?

A vulnerability in web services of Progress Sitefinity versions 8.0.5700 to 13.3.7652 allows remote authenticated attackers to retrieve plain-text credentials used for connecting to the Sitefinity Insight service. To exploit this vulnerability, an attacker must have active integration with Sitefinity Insight, a non-default site configuration, and valid back-end authorization, thereby increasing the attack surface for compromised credentials.

Affected Version(s)

Sitefinity 8.0.5700 < 13.3.7652

References

CVSS V3.1

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.