


Perceptive Security
SOC/SIEM Consultancy

CWE-284: Improper Access Control in web services in Progress Sitefinity 15.4.8623 before 15.4.8630 allows a remote unauthenticated attacker to access content th…
Published:
1 June 2026 at 22:00:00
Alert date:
2 June 2026 at 15:00:52
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications
A critical improper access control vulnerability (CWE-284) affects Progress Sitefinity web services in versions 15.4.8623 before 15.4.8630. The vulnerability allows remote unauthenticated attackers to access restricted content, leading to full compromise of confidentiality, integrity, and availability. This represents a complete security bypass that can result in total system compromise. The vulnerability is part of a broader security advisory addressing multiple CVEs in Sitefinity. Organizations using affected versions should immediately upgrade to version 15.4.8630 or later.
Technical details
Mitigation steps:
Affected products:
Progress Sitefinity
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-7198
https://community.progress.com/s/article/Sitefinity-Security-Advisory-for-Addressing-Security-Vulnerabilities-CVE-2026-7312-CVE-2026-7198-CVE-2026-7195-CVE-2026-7201-CVE-2026-7313-May-2026
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
