CVE-2026-7198
Progress Sitefinity versions before 15.4.8630 contain a critical flaw that lets anyone on the internet read, modify, or delete restricted content. This can lead to full compromise of the site’s data and availability. The issue is fixed in version 15.4.8630 and later.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Progress Sitefinity 15.4.8623 and earlier (before 15.4.8630).
Real-world impact
An attacker could read confidential data, alter or delete content, and disrupt the site, effectively taking full control of the installation.
Why this severity
The CVSS score of 9.8 reflects that the vulnerability is exploitable over the network with no authentication, and it can compromise confidentiality, integrity, and availability, making it a critical risk.
What to do about it
- 01Upgrade to Progress Sitefinity version 15.4.8630 or later.
- 02Restart the application after the upgrade.
NVD description indicates fix in 15.4.8630 or later.
Timeline
- Jun 2, 2026 · Jun 2, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 22, 2026 · 13d agoAdvisory updatedThe NVD record was last revised.
- Jul 25, 2026 · 10d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- community.progress.com/s/article/Sitefinity-Securi…vendor advisory