CVE-2026-7201: CWE-639: Authorization Bypass Through User-Controlled Key in web services in Progress Sitefinity
CWE-639: Authorization Bypass Through User-Controlled Key in web services in Progress Sitefinity 15.2.x before 15.2.8441, 15.3.x before 15.3.8531, and 15.4.x before 15.4.8630 allows a remote authenticated attacker to modify account properties of other users, potentially leading to account compromise. Successful exploitation requires knowledge of values that are not generally exposed to low-privileged users.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7201?
CVE-2026-7201 has a severity score of 8.8, categorizing it as high risk.
How do I fix CVE-2026-7201?
To fix CVE-2026-7201, update your Progress Sitefinity to version 15.2.8441 or later, 15.3.8531 or later, or 15.4.8630 or later.
What type of attack does CVE-2026-7201 allow?
CVE-2026-7201 allows a remote authenticated attacker to bypass authorization and modify account properties of other users.
Which versions of Progress Sitefinity are affected by CVE-2026-7201?
Progress Sitefinity versions before 15.2.8441, 15.3.8531, and 15.4.8630 are affected by CVE-2026-7201.
What is CWE-639 in relation to CVE-2026-7201?
CWE-639 refers to authorization bypass vulnerabilities that allow attackers to use user-controlled keys to gain unauthorized access, as seen in CVE-2026-7201.