Skip to content
CVE-2026-7195 - Exploits & Severity

CVE-2026-7195 - Exploits & Severity

Feedly June 2, 2026

Improper input validation in web services in Progress Sitefinity (versions 14.1.x through 14.3.x, 14.4.x before 14.4.8152, 15.0.x before 15.0.8234, 15.1.x before 15.1.8335, 15.2.x before 15.2.8441, 15.3.x before 15.3.8531, and 15.4.x before 15.4.8630) allows compromise of user account integrity and confidentiality. Exploitation requires user interaction and a non-default site configuration.

An unauthenticated remote attacker can compromise the integrity and confidentiality of user accounts through specially crafted requests that exploit improper input validation, provided the victim interacts with the attack vector and the Sitefinity instance uses a non-default configuration.

There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.

Patches are available. Update to Sitefinity 14.4.8152, 15.0.8234, 15.1.8335, 15.2.8441, 15.3.8531, 15.4.8630 or later.

Prioritize upgrading Progress Sitefinity installations to the patched versions. For systems that cannot be immediately patched, review and enforce default security configurations, monitor for exploitation attempts targeting web service endpoints, and implement network-level access controls to restrict access to Sitefinity web services if possible.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

NVD published the first details for CVE-2026-7195

A CVSS base score of 8.8 has been assigned.

Feedly found the first article mentioning CVE-2026-7195 . See article

GitHub Advisories released a security advisory .

A high-severity vulnerability with a CVSS score of 8.8 affects various versions of Progress Sitefinity, allowing remote unauthenticated attackers to compromise user account integrity and confidentiality through improper input validation. Currently, there are no public proof-of-concept exploits, but organizations are advised to upgrade to patched versions to mitigate the risk. The exploitation requires user interaction and specific non-default site configurations, highlighting the need for careful monitoring and configuration management. See article

[GHSA-5846-8mmv-m39j] CWE-20: Improper Input Validation in web services in Progress Sitefinity 14.1.x

CVE-2026-7195 - Exploits & Severity - Feedly

CVE-2026-7195: CWE-20: Improper Input Validation in web services in Prog…

CVE-2026-7195 - Exploits & Severity - Feedly

CVE-2026-7195: CWE-20: Improper Input Validation in web services in Prog…

Collect, analyze, and vulnerability reports faster using AI

Extracted Entities