


Perceptive Security
SOC/SIEM Consultancy

CWE-284: Improper Access Control in web services in Progress Sitefinity 15.4.8623 before 15.4.8630 allows a remote unauthenticated attacker to access content th…
Published:
1 juni 2026 om 22:00:00
Alert date:
2 juni 2026 om 16:01:47
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications, Identity & Access
CVE-2026-7198 is an improper access control vulnerability in Progress Sitefinity web services affecting versions 15.4.8623 before 15.4.8630. The vulnerability allows remote unauthenticated attackers to access restricted content, resulting in complete compromise of confidentiality, integrity, and availability. This is classified as CWE-284 and appears to be part of a broader security advisory addressing multiple CVEs in Sitefinity. The vulnerability poses a critical risk due to the potential for full system compromise without authentication requirements.
Technical details
Mitigation steps:
Affected products:
Progress Sitefinity
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-7198
https://community.progress.com/s/article/Sitefinity-Security-Advisory-for-Addressing-Security-Vulnerabilities-CVE-2026-7312-CVE-2026-7198-CVE-2026-7195-CVE-2026-7201-CVE-2026-7313-May-2026
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
