CVE-2026-7195: CWE-20: Improper Input Validation in web services in Progress Sitefinity
CWE-20: Improper Input Validation in web services in Progress Sitefinity 14.1.x through 14.3.x, 14.4.x before 14.4.8152, 15.0.x before 15.0.8234, 15.1.x before 15.1.8335, 15.2.x before 15.2.8441, 15.3.x before 15.3.8531, and 15.4.x before 15.4.8630 allows a remote unauthenticated attacker to compromise the integrity and confidentiality of user accounts. Successful exploitation requires user interaction and a non-default site configuration.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7195?
CVE-2026-7195 has a high severity rating of 8.8.
How do I fix CVE-2026-7195?
To fix CVE-2026-7195, update your Progress Sitefinity installation to the latest version that addresses this vulnerability.
What type of vulnerability is CVE-2026-7195?
CVE-2026-7195 is classified as an improper input validation vulnerability.
Who is affected by CVE-2026-7195?
CVE-2026-7195 affects Progress Sitefinity versions 14.1.x through 14.4.x, 15.0.x to 15.4.x prior to specific patch versions.
What can an attacker do with CVE-2026-7195?
An unauthenticated remote attacker can exploit CVE-2026-7195 to compromise data integrity and availability.