8.8
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Description
CWE-639: Authorization Bypass Through User-Controlled Key in web services in Progress Sitefinity 15.2.x before 15.2.8441, 15.3.x before 15.3.8531, and 15.4.x before 15.4.8630 allows a remote authenticated attacker to modify account properties of other users, potentially leading to account compromise. Successful exploitation requires knowledge of values that are not generally exposed to low-privileged users.
AI Analysis
Authorization bypass vulnerability in Progress Sitefinity web services, allowing remote authenticated attackers to modify account properties of other users.
Basic Information
ID
CVE-2026-7201
Source
ProgressSoftware
Published
Jun 2, 2026 at 13:07
Affected Product
Vendor
Progress Software
Product
Sitefinity
Version
15.2.8400
Affected Versions
Progress Software Sitefinity 15.2.8400
Progress Software Sitefinity 15.3.8500
Progress Software Sitefinity 15.4.8600
Progress Software Sitefinity 15.3.8500
Progress Software Sitefinity 15.4.8600
CWE Classification
AI Assessment
AI Score
8.8 / 10
AI Severity
High
Vendor
Progress Software
Product
Sitefinity
Version
15.2.x before 15.2.8441, 15.3.x before 15.3.8531, 15.4.x before 15.4.8630